Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.
2008-02-27T19:44:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netwin | surgemail | ≤ 38k4 | Yes |
Application | netwin | surgemail | 1.8a | Yes |
Application | netwin | surgemail | 1.8b3 | Yes |
Application | netwin | surgemail | 1.8d | Yes |
Application | netwin | surgemail | 1.8e | Yes |
Application | netwin | surgemail | 1.8g3 | Yes |
Application | netwin | surgemail | 1.9 | Yes |
Application | netwin | surgemail | 1.9b2 | Yes |
Application | netwin | surgemail | 2.0a2 | Yes |
Application | netwin | surgemail | 2.0c | Yes |
Application | netwin | surgemail | 2.0e | Yes |
Application | netwin | surgemail | 2.0g2 | Yes |
Application | netwin | surgemail | 2.1a | Yes |
Application | netwin | surgemail | 2.1c7 | Yes |
Application | netwin | surgemail | 2.2a6 | Yes |
Application | netwin | surgemail | 2.2c9 | Yes |
Application | netwin | surgemail | 2.2c10 | Yes |
Application | netwin | surgemail | 2.2g2 | Yes |
Application | netwin | surgemail | 2.2g3 | Yes |
Application | netwin | surgemail | 3.0a | Yes |
Application | netwin | surgemail | 3.0c2 | Yes |
Application | netwin | surgemail | 3.8f3 | Yes |
Application | netwin | surgemail | 39a | Yes |
Application | netwin | surgemail | beta_39a | Yes |
Application | netwin | webmail | ≤ 3.1s | Yes |