Vulnerabilities (CVE)

Filtered by vendor Netwin Subscribe
Total 50 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-6457 1 Netwin 1 Surgemail 2023-12-10 5.0 MEDIUM N/A
Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (crash) via a long Host header.
CVE-2005-1516 1 Netwin 1 Dmail 2023-12-10 7.5 HIGH N/A
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.
CVE-2004-2547 1 Netwin 2 Surgemail, Webmail 2023-12-10 2.6 LOW N/A
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message.
CVE-2005-0845 1 Netwin 1 Surgemail 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.
CVE-2004-2548 1 Netwin 2 Surgemail, Webmail 2023-12-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547).
CVE-2005-1034 1 Netwin 1 Surgeftp 2023-12-10 5.0 MEDIUM N/A
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.
CVE-2004-2318 1 Netwin 1 Surgeftp 2023-12-10 5.0 MEDIUM N/A
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
CVE-2005-1714 1 Netwin 1 Surgemail 2023-12-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2005-1478 1 Netwin 1 Dmail 2023-12-10 7.5 HIGH N/A
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.
CVE-2005-0846 1 Netwin 1 Surgemail 2023-12-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.
CVE-2004-2537 1 Netwin 1 Surgemail 2023-12-10 10.0 HIGH N/A
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."
CVE-2000-0422 1 Netwin 1 Dmail 2023-12-10 7.5 HIGH N/A
Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.
CVE-2001-1354 1 Netwin 2 Dmail, Surgeftp 2023-12-10 4.6 MEDIUM N/A
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
CVE-2000-0610 1 Netwin 2 Cwmail, Dmailweb 2023-12-10 5.0 MEDIUM N/A
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.
CVE-2004-2253 1 Netwin 1 Surgeldap 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and earlier allows remote attackers to read arbitrary files via a .. in the page parameter of the show command.
CVE-2001-0697 1 Netwin 1 Surgeftp 2023-12-10 5.0 MEDIUM N/A
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
CVE-2000-0608 1 Netwin 2 Cwmail, Dmailweb 2023-12-10 5.0 MEDIUM N/A
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).
CVE-2000-0611 1 Netwin 2 Cwmail, Dmailweb 2023-12-10 5.0 MEDIUM N/A
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
CVE-2000-0609 1 Netwin 2 Cwmail, Dmailweb 2023-12-10 5.0 MEDIUM N/A
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.
CVE-2002-0273 1 Netwin 1 Cwmail 2023-12-10 4.6 MEDIUM N/A
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.