CVE-2008-7182
medium · 4Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.
4
CVSS
24.3%
EPSS (exploit prob.)
98th
EPSS percentile
2009-09-08
Published
AV:N/AC:L/Au:S/C:N/I:N/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| netwin | surgemail | 3.9e |
Check a specific version with /api/v1/cve/match.
References
- http://www.netwinsite.com/surgemail/help/updates.htm
- http://www.securityfocus.com/archive/1/496482
- http://www.securityfocus.com/bid/30000
- https://www.exploit-db.com/exploits/5968
- http://www.netwinsite.com/surgemail/help/updates.htm
- http://www.securityfocus.com/archive/1/496482
- http://www.securityfocus.com/bid/30000
- https://www.exploit-db.com/exploits/5968
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-7182