Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Surgeftp MEDIUM 6.1
CVE-2017-17933

cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or us…

No fix yet
Fix from $1,600 2017-12-29
Surgeftp HIGH 7.5
CVE-2013-4742

Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a …

Fix: after 2.3b1
Fix from $1,950 2013-08-09
Smsgate MEDIUM 5.0
CVE-2008-5421

The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large int…

Fix: after 1.1n
Fix from $1,600 2008-12-11
Surgemail MEDIUM 5.0
CVE-2008-2859

Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) vi…

Fix: after 3.9g
Fix from $1,600 2008-06-25
Surgemail HIGH 9.0
CVE-2008-1497EPSS 6%

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…

No fix yet
Fix from $1,950 2008-03-25
Surgemail HIGH 9.0
CVE-2008-1498EPSS 8%

Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code v…

Fix: after 3.8k4
Fix from $1,950 2008-03-25
Surgemail HIGH 7.5
CVE-2008-1055EPSS 8%

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers t…

Fix: after 38k4
Fix from $1,950 2008-02-27
Surgeftp MEDIUM 6.4
CVE-2008-1052EPSS 7%

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large…

Mitigation only
Fix from $1,600 2008-02-27
Surgemail MEDIUM 6.4
CVE-2008-1054EPSS 7%

Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …

No fix yet
Fix from $1,600 2008-02-27
Surgemail MEDIUM 5.0
CVE-2007-6457

Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (crash) via a long Host hea…

No fix yet
Fix from $1,600 2007-12-20
Surgemail HIGH 10.0
CVE-2007-4372

Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is bas…

No fix yet
Fix from $1,950 2007-08-16
Surgemail MEDIUM 6.0
CVE-2007-4377EPSS 5%

Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to t…

No fix yet
Fix from $1,600 2007-08-16
Surgeftp HIGH 8.5
CVE-2007-3768

The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a …

Fix: after 2.3a1
Fix from $1,950 2007-07-15
Surgeftp MEDIUM 5.8
CVE-2007-3769

Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to in…

Fix: after 2.3a1
Fix from $1,600 2007-07-15
Surgemail HIGH 7.5
CVE-2007-2655

Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string v…

Patch available
Fix from $1,950 2007-05-14
Webnews HIGH 7.5
CVE-2006-5100

PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2006-10-03
Dmail HIGH 7.5
CVE-2005-1478

Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the …

No fix yet
Fix from $1,950 2005-05-11
Dmail HIGH 7.5
CVE-2005-1516

DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with …

Mitigation only
Fix from $1,950 2005-05-11
Surgeftp MEDIUM 5.0
CVE-2005-1034

SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.

Patch available
Fix from $1,600 2005-05-02
Surgemail HIGH 10.0
CVE-2004-2537

Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."

Patch available
Fix from $1,950 2004-12-31
Surgeldap HIGH 7.5
CVE-2004-2254EPSS 8%

SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface…

Patch available
Fix from $1,950 2004-12-31
Surgeldap MEDIUM 5.0
CVE-2004-2253EPSS 7%

Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page para…

No fix yet
Fix from $1,600 2004-12-31
Webnews HIGH 7.5
CVE-2002-0290

Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.

Patch available
Fix from $1,950 2002-05-31
Webnews HIGH 7.5
CVE-2002-0310

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows …

Mitigation only
Fix from $1,950 2002-05-31
Surgeftp MEDIUM 5.0
CVE-2001-0696

NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device nam…

Patch available
Fix from $1,600 2001-09-20
Surgeftp MEDIUM 5.0
CVE-2001-0697EPSS 7%

NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.

Fix: after 1.1h
Fix from $1,600 2001-09-20
Surgeftp MEDIUM 5.0
CVE-2001-0698

Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ..…

Patch available
Fix from $1,600 2001-09-20
Surgeftp HIGH 10.0
CVE-2001-1356

NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers …

Mitigation only
Fix from $1,950 2001-08-04
Dmail HIGH 10.0
CVE-2001-1355

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could all…

Mitigation only
Fix from $1,950 2001-07-20
Netauth MEDIUM 5.0
CVE-2000-0782EPSS 8%

netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Fix: after 4.2
Fix from $1,600 2000-10-20