← Back

CVE-2008-1055

nvd nist
Published: Feb 27, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

Affected (25)

2 products
Surgemail
Webmail
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Netwin
Up to 38k4
Version 1.8a
Version 1.8b3
Version 1.8d
Version 1.8e
Version 1.8g3
Version 1.9
Version 1.9b2
Version 2.0a2
Version 2.0c
Version 2.0e
Version 2.0g2
Version 2.1a
Version 2.1c7
Version 2.2a6
Version 2.2c10
Version 2.2c9
Version 2.2g2
Version 2.2g3
Version 3.0a
Version 3.0c2
Version 3.8f3
Version 39a
Version beta_39a
Up to 3.1s

References (18)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.