← Back

Cwmail

cwmail

Vendor: Netwin • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netwin
1Cwmail
Apr 16, 2026
May 31, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 23, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 23, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 21, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 21, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).