Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Surgeftp MEDIUM 6.1
CVE-2017-17933

cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or us…

No fix yet
Fix from $1,600 2017-12-29
Surgemail HIGH 9.0
CVE-2008-1497EPSS 6%

Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…

No fix yet
Fix from $1,950 2008-03-25
Surgeftp MEDIUM 6.4
CVE-2008-1052EPSS 7%

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large…

Mitigation only
Fix from $1,600 2008-02-27
Surgemail MEDIUM 6.4
CVE-2008-1054EPSS 7%

Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …

No fix yet
Fix from $1,600 2008-02-27
Surgemail MEDIUM 5.0
CVE-2007-6457

Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (crash) via a long Host hea…

No fix yet
Fix from $1,600 2007-12-20
Surgemail HIGH 10.0
CVE-2007-4372

Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is bas…

No fix yet
Fix from $1,950 2007-08-16
Surgemail MEDIUM 6.0
CVE-2007-4377EPSS 5%

Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to t…

No fix yet
Fix from $1,600 2007-08-16
Webnews HIGH 7.5
CVE-2006-5100

PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2006-10-03
Dmail HIGH 7.5
CVE-2005-1478

Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the …

No fix yet
Fix from $1,950 2005-05-11
Dmail HIGH 7.5
CVE-2005-1516

DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with …

Mitigation only
Fix from $1,950 2005-05-11
Surgeldap MEDIUM 5.0
CVE-2004-2253EPSS 7%

Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page para…

No fix yet
Fix from $1,600 2004-12-31
Webnews HIGH 7.5
CVE-2002-0310

Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows …

Mitigation only
Fix from $1,950 2002-05-31
Surgeftp HIGH 10.0
CVE-2001-1356

NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers …

Mitigation only
Fix from $1,950 2001-08-04
Dmail HIGH 10.0
CVE-2001-1355

Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could all…

Mitigation only
Fix from $1,950 2001-07-20
Cwmail MEDIUM 5.0
CVE-2000-0609

NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.

Mitigation only
Fix from $1,600 2000-06-21
Dnews MEDIUM 5.0
CVE-2000-0423EPSS 8%

Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.

Mitigation only
Fix from $1,600 2000-05-05
Dmail HIGH 7.5
CVE-2000-0422

Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.

Mitigation only
Fix from $1,950 2000-05-04