Skip to main content

Vendor/product archive

netwin / dmail CVEs

Beta · best-effort

6 CVEs tagged to netwin / dmail2 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2005-1478

Published May 11, 2005

Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1516

Published May 11, 2005

DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, wh…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1354

Published Jul 20, 2001

NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to de…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1355

Published Jul 20, 2001

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0490

Published Jun 1, 2000

Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0422

Published May 4, 2000

Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1