CVE-2008-1055
27.02.2008, 19:44
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.Enginsight
Vendor | Product | Version |
---|---|---|
netwin | surgemail | 𝑥 ≤ 38k4 |
netwin | surgemail | 1.8a:a |
netwin | surgemail | 1.8b3:b3 |
netwin | surgemail | 1.8d:d |
netwin | surgemail | 1.8e:e |
netwin | surgemail | 1.8g3:g3 |
netwin | surgemail | 1.9 |
netwin | surgemail | 1.9b2:b2 |
netwin | surgemail | 2.0a2:a2 |
netwin | surgemail | 2.0c:c |
netwin | surgemail | 2.0e:e |
netwin | surgemail | 2.0g2:g2 |
netwin | surgemail | 2.1a:a |
netwin | surgemail | 2.1c7:c7 |
netwin | surgemail | 2.2a6:a6 |
netwin | surgemail | 2.2c9:c9 |
netwin | surgemail | 2.2c10:c10 |
netwin | surgemail | 2.2g2:g2 |
netwin | surgemail | 2.2g3:g3 |
netwin | surgemail | 3.0a:a |
netwin | surgemail | 3.0c2:c2 |
netwin | surgemail | 3.8f3:f3 |
netwin | webmail | 𝑥 ≤ 3.1s |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References