Filtered by vendor Netwin
                         Subscriptions
                    
                    
                
                    Total
                    52 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2007-4377 | 1 Netwin | 1 Surgemail | 2025-04-09 | N/A | 
| Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372. | ||||
| CVE-2008-1052 | 1 Netwin | 1 Surgeftp | 2025-04-09 | N/A | 
| The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails. | ||||
| CVE-2007-3769 | 1 Netwin | 1 Surgeftp | 2025-04-09 | N/A | 
| Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account. | ||||
| CVE-2001-1356 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A | 
| NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021. | ||||
| CVE-2001-0696 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A | 
| NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. | ||||
| CVE-2002-0290 | 1 Netwin | 1 Webnews | 2025-04-03 | N/A | 
| Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument. | ||||
| CVE-2004-2548 | 1 Netwin | 2 Surgemail, Webmail | 2025-04-03 | N/A | 
| Multiple cross-site scripting (XSS) vulnerabilities in NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to inject arbitrary web script or HTML via (a) a URI containing the script, or (b) the username field in the login form. NOTE: it is possible that the first attack vector is resultant from the error message issue (CVE-2004-2547). | ||||
| CVE-2004-2254 | 1 Netwin | 1 Surgeldap | 2025-04-03 | N/A | 
| SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter. | ||||
| CVE-2000-0422 | 1 Netwin | 1 Dmail | 2025-04-03 | N/A | 
| Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter. | ||||
| CVE-2004-2547 | 1 Netwin | 2 Surgemail, Webmail | 2025-04-03 | N/A | 
| NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error message. | ||||
| CVE-2000-0423 | 1 Netwin | 1 Dnews | 2025-04-03 | N/A | 
| Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. | ||||
| CVE-2000-0490 | 1 Netwin | 1 Dmail | 2025-04-03 | N/A | 
| Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. | ||||
| CVE-2000-0608 | 1 Netwin | 2 Cwmail, Dmailweb | 2025-04-03 | N/A | 
| NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost). | ||||
| CVE-2000-0609 | 1 Netwin | 2 Cwmail, Dmailweb | 2025-04-03 | N/A | 
| NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter. | ||||
| CVE-2001-0697 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A | 
| NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | ||||
| CVE-2001-0698 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A | 
| Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. | ||||
| CVE-2001-1354 | 1 Netwin | 2 Dmail, Surgeftp | 2025-04-03 | N/A | 
| NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password. | ||||
| CVE-2002-0273 | 1 Netwin | 1 Cwmail | 2025-04-03 | N/A | 
| Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter. | ||||
| CVE-2004-2318 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A | 
| The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter. | ||||
| CVE-2004-2537 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A | 
| Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." | ||||