CyberSec.Space Logo
Back to CVE Browser

CVE-2008-1055

HIGH
7.5
CVSS Severity Score
EPSS Score0.1300%
EPSS Percentile18.70th
PublishedFeb 27, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

Affected Platforms (CPE)

πŸ“¦
Netwin

Surgemail

<= 38k4
πŸ“¦
Netwin

Surgemail

= 1.8a
πŸ“¦
Netwin

Surgemail

= 1.8b3
πŸ“¦
Netwin

Surgemail

= 1.8d
πŸ“¦
Netwin

Surgemail

= 1.8e
πŸ“¦
Netwin

Surgemail

= 1.8g3
πŸ“¦
Netwin

Surgemail

= 1.9
πŸ“¦
Netwin

Surgemail

= 1.9b2
πŸ“¦
Netwin

Surgemail

= 2.0a2
πŸ“¦
Netwin

Surgemail

= 2.0c
πŸ“¦
Netwin

Surgemail

= 2.0e
πŸ“¦
Netwin

Surgemail

= 2.0g2
πŸ“¦
Netwin

Surgemail

= 2.1a
πŸ“¦
Netwin

Surgemail

= 2.1c7
πŸ“¦
Netwin

Surgemail

= 2.2a6
πŸ“¦
Netwin

Surgemail

= 2.2c9
πŸ“¦
Netwin

Surgemail

= 2.2c10
πŸ“¦
Netwin

Surgemail

= 2.2g2
πŸ“¦
Netwin

Surgemail

= 2.2g3
πŸ“¦
Netwin

Surgemail

= 3.0a
πŸ“¦
Netwin

Surgemail

= 3.0c2
πŸ“¦
Netwin

Surgemail

= 3.8f3
πŸ“¦
Netwin

Surgemail

= 39a
πŸ“¦
Netwin

Surgemail

= beta_39a
πŸ“¦
Netwin

Webmail

<= 3.1s

References & Advisories

Related Vulnerabilities