← Back

Netwin

netwin

48 CVEs • 12 products

Products (12)

Click to collapse
Toggle
Surgemail
surgemail
Surgeftp
surgeftp
Dmail
dmail
Cwmail
cwmail
Dmailweb
dmailweb
Webmail
webmail
Webnews
webnews
Surgeldap
surgeldap
Dnews
dnews
Netauth
netauth
Dnewsweb
dnewsweb
Smsgate
smsgate

CVEs (48)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netwin
1Netauth
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 23, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 23, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 21, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.
1Netwin
2Cwmail
Dmailweb
Apr 16, 2026
Jun 21, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).
1Netwin
1Dmail
Apr 16, 2026
Jun 1, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.
1Netwin
1Dnews
Apr 16, 2026
May 5, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.
1Netwin
1Dmail
Apr 16, 2026
May 4, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.