Vulnerabilities
Vulnerable Software
Netwin:  >> Surgemail  >> 3.9e  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.
CVSS Score
4.3
EPSS Score
0.021
Published
2011-01-07
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.
CVSS Score
4.0
EPSS Score
0.134
Published
2009-09-08
Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."
CVSS Score
5.0
EPSS Score
0.044
Published
2008-06-25


Contact Us

Shodan ® - All rights reserved