Skip to main content

Vendor/product archive

netwin / surgemail CVEs

Beta · best-effort

18 CVEs tagged to netwin / surgemail4 Critical, 2 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2012-2575

Published Sep 17, 2012

Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IFRAME element in the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3201

Published Jan 7, 2011

Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgew…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7182

Published Sep 8, 2009

Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2859

Published Jun 25, 2008

Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1497

Published Mar 25, 2008

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB c…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1498

Published Mar 25, 2008

Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to th…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1054

Published Feb 27, 2008

Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attack…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1055

Published Feb 27, 2008

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6457

Published Dec 20, 2007

Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (crash) via a long Host header.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4372

Published Aug 16, 2007

Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4377

Published Aug 16, 2007

Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2655

Published May 14, 2007

Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1714

Published May 24, 2005

Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0845

Published May 2, 2005

Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0846

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) me…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2537

Published Dec 31, 2004

Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-2547

Published Dec 31, 2004

NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2548

Published Dec 31, 2004

Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1