渐进机器人(Progressive Robot)hMailServer 6.3.2 至 6.3.5 版本的 Web 邮件系统中存在证书验证不当的漏洞,允许远程未认证的攻击者实现如下攻击效果:攻击者发送给该账户的 S/MIME 加密邮件,在后续由该账户转发给其他通信方时,会被错误地使用攻击者的公钥进行加密。 当收件人打开一条已签名的邮件时,Web 邮件系统会保存该邮件签名者的证书,用于对回复邮件进行加密,而不论服务器是否验证通过该证书的信任链。系统在保存证书时,优先采用证书中列出的第一个电子邮件地址,而非邮件“Fro
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progressive Robot Ltd | hMailServer | 6.3.2 ~ 6.3.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103647 | 8.0 HIGH | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hM |
| CVE-2026-103010 | 7.8 HIGH | Heap-based Buffer Overflow in hMailServer |
| CVE-2026-104660 | 7.8 HIGH | Missing Authorization in hMailServer |
| CVE-2026-104658 | 7.8 HIGH | Reliance on Untrusted Inputs in a Security Decision in hMailServer |
| CVE-2026-107573 | 7.8 HIGH | Incorrect Default Permissions in hMailServer |
| CVE-2026-107576 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107577 | 7.5 HIGH | Loop with Unreachable Exit Condition ('Infinite Loop') in hMailServer |
| CVE-2026-107574 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107579 | 7.5 HIGH | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-104659 | 7.5 HIGH | Origin Validation Error in hMailServer |
| CVE-2026-103649 | 7.5 HIGH | Synchronous Access of Remote Resource without Timeout in hMailServer |
| CVE-2026-107584 | 7.4 HIGH | Not Failing Securely ('Failing Open') in hMailServer |
| CVE-2026-104704 | 7.4 HIGH | Cleartext Transmission of Sensitive Information in hMailServer |
| CVE-2026-107578 | 6.7 MEDIUM | Improper Link Resolution Before File Access ('Link Following') in hMailServer |
| CVE-2026-107583 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107572 | 6.5 MEDIUM | Inefficient Regular Expression Complexity in hMailServer |
| CVE-2026-107581 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107582 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-107580 | 6.5 MEDIUM | Inefficient Algorithmic Complexity in hMailServer |
| CVE-2026-103011 | 6.5 MEDIUM | Heap-based Buffer Overflow in hMailServer |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet