CVE-2008-1055

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
netwinsurgemail
𝑥
≤ 38k4
netwinsurgemail
1.8a:a
netwinsurgemail
1.8b3:b3
netwinsurgemail
1.8d:d
netwinsurgemail
1.8e:e
netwinsurgemail
1.8g3:g3
netwinsurgemail
1.9
netwinsurgemail
1.9b2:b2
netwinsurgemail
2.0a2:a2
netwinsurgemail
2.0c:c
netwinsurgemail
2.0e:e
netwinsurgemail
2.0g2:g2
netwinsurgemail
2.1a:a
netwinsurgemail
2.1c7:c7
netwinsurgemail
2.2a6:a6
netwinsurgemail
2.2c9:c9
netwinsurgemail
2.2c10:c10
netwinsurgemail
2.2g2:g2
netwinsurgemail
2.2g3:g3
netwinsurgemail
3.0a:a
netwinsurgemail
3.0c2:c2
netwinsurgemail
3.8f3:f3
netwinwebmail
𝑥
≤ 3.1s
𝑥
= Vulnerable software versions