7.8

CVSS4.0

CVE-2026-29139 - GINA State Confusion Account Takeover

SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.

๐Ÿ“… Published: April 2, 2026, 8:52 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.8

CVSS4.0

CVE-2026-29144 - Unicode Subject Tags

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.

๐Ÿ“… Published: April 2, 2026, 8:50 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.8

CVSS4.0

CVE-2026-29143 - S/MIME Decryption Impersonation

SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.

๐Ÿ“… Published: April 2, 2026, 8:49 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.8

CVSS3.1

CVE-2026-0634 - Code Execution in AssistFeedbackService on TECNO Pova7 Pro 5G

Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as system via command injection.

๐Ÿ“… Published: April 2, 2026, 8:48 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.3

CVSS4.0

CVE-2026-29138 - PGP Decryption Sender LDAP Injection

SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.

๐Ÿ“… Published: April 2, 2026, 8:47 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

4.9

CVSS4.0

CVE-2026-29131 - PGP Decryption Recipient LDAP Injection

SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.

๐Ÿ“… Published: April 2, 2026, 8:46 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

6.3

CVSS4.0

CVE-2026-29142 - Plaintext secure-mail.html

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.

๐Ÿ“… Published: April 2, 2026, 8:44 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-29137 - Long Subject Untagging

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.

๐Ÿ“… Published: April 2, 2026, 8:42 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

7.7

CVSS4.0

CVE-2026-29141 - Bounded Subject Tag Sanitization

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].

๐Ÿ“… Published: April 2, 2026, 8:34 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.

5.3

CVSS4.0

CVE-2026-29135 - Webmail Password Tag Sanitization Bypass

SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.

๐Ÿ“… Published: April 2, 2026, 8:31 a.m. ๐Ÿ”„ Last Modified: April 3, 2026, 4:10 p.m.
Total resulsts: 343939
Page 218 of 34,394
ยซ previous page ยป next page
Filters