在 Progressive Robot 公司开发的 hMailServer 6.0.0 至 6.3.5 版本中,MIME 消息处理存在低效的算法复杂度和非终止循环漏洞,远程未认证攻击者可通过发送恶意邮件使邮件服务不可用。具体而言,当删除一个值为空且后跟分号的 MIME 头参数时(例如 Content-Disposition 头中设置为 'filename=a.bat; filename=;'),程序会进入无限循环,导致工作线程持续满载运行,直到服务器重启才能恢复;该触发场景出现在附件阻止模块重命名被阻止的附件时,或
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progressive Robot Ltd | hMailServer | 6.0.0 ~ 6.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103647 | 8.0 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM |
| CVE-2026-103010 | 7.8 HIGH | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107573 | 7.8 HIGH | Incorrect Default Permissions in hMailServer |
| CVE-2026-104658 | 7.8 HIGH | Reliance on Untrusted Inputs in a Security Decision in hMailServer |
| CVE-2026-104660 | 7.8 HIGH | Missing Authorization in hMailServer |
| CVE-2026-107576 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107574 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107579 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-103649 | 7.5 HIGH | Synchronous Access of Remote Resource without Timeout in hMailServer |
| CVE-2026-104659 | 7.5 HIGH | Origin Validation Error in hMailServer |
| CVE-2026-107584 | 7.4 HIGH | Not Failing Securely ('Failing Open') in hMailServer |
| CVE-2026-104704 | 7.4 HIGH | Cleartext Transmission of Sensitive Information in hMailServer |
| CVE-2026-107578 | 6.7 MEDIUM | Improper Link Resolution Before File Access ('Link Following') in hMailServer |
| CVE-2026-107583 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-103011 | 6.5 MEDIUM | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-107572 | 6.5 MEDIUM | Inefficient Regular Expression Complexity in hMailServer |
| CVE-2026-107581 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107582 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107580 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107587 | 5.9 MEDIUM | Improper Certificate Validation in hMailServer |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet