Skip to content
Noroxi

NetWin records

50 published records for vendor netwin.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
11
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

50 records
  • Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN r

    CriticalCVSS 10.0Proof of conceptEPSS 6%

    netwin · dmailJun 1, 2000

  • NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote a

    CriticalCVSS 10.0No exploitEPSS 4%

    netwin · surgeftpAug 4, 2001

  • Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages,

    CriticalCVSS 10.0No exploitEPSS 4%

    netwin · dmailJul 20, 2001

  • Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."

    CriticalCVSS 10.0No exploitEPSS 2%

    netwin · surgemailDec 31, 2004

  • Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.

    CriticalCVSS 10.0No exploitEPSS 1%

    netwin · surgemailAug 16, 2007

  • CVE-2008-1498
    38Monitor

    Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitra

    CriticalCVSS 9.0Proof of conceptEPSS 8%

    netwin · surgemailMar 25, 2008

  • CVE-2008-1497
    38Monitor

    Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrar

    CriticalCVSS 9.0No exploitEPSS 6%

    netwin · surgemailMar 25, 2008

  • CVE-2007-3768
    34Monitor

    The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed respo

    HighCVSS 8.5No exploitEPSS 2%

    netwin · surgeftpJul 15, 2007

  • CVE-2004-2254
    33Monitor

    SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration

    HighCVSS 7.5Proof of conceptEPSS 8%

    netwin · surgeldapDec 31, 2004

  • CVE-2008-1055
    32Monitor

    Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote at

    HighCVSS 7.5Proof of conceptEPSS 8%

    netwin · surgemailFeb 27, 2008

  • CVE-2005-1478
    31Monitor

    Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifier

    HighCVSS 7.5No exploitEPSS 5%

    netwin · dmailMay 11, 2005

  • CVE-2013-4742
    31Monitor

    Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co

    HighCVSS 7.5No exploitEPSS 4%

    netwin · surgeftpAug 9, 2013

  • CVE-2007-2655
    31Monitor

    Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format

    HighCVSS 7.5No exploitEPSS 4%

    netwin · surgemailMay 14, 2007

  • CVE-2006-5100
    31Monitor

    PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute ar

    HighCVSS 7.5Proof of conceptEPSS 4%

    netwin · webnewsOct 3, 2006

  • CVE-2002-0290
    31Monitor

    Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.

    HighCVSS 7.5No exploitEPSS 3%

    netwin · webnewsMay 31, 2002

  • CVE-2000-0422
    31Monitor

    Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.

    HighCVSS 7.5No exploitEPSS 2%

    netwin · dmailMay 4, 2000

  • CVE-2005-1516
    30Monitor

    DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog comm

    HighCVSS 7.5No exploitEPSS 2%

    netwin · dmailMay 11, 2005

  • CVE-2002-0310
    30Monitor

    Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whic

    HighCVSS 7.5No exploitEPSS 2%

    netwin · webnewsMay 31, 2002

  • CVE-2008-1054
    27Monitor

    Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earl

    MediumCVSS 6.4Proof of conceptEPSS 7%

    netwin · surgemailFeb 27, 2008

  • CVE-2008-1052
    27Monitor

    The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vi

    MediumCVSS 6.4Proof of conceptEPSS 7%

    netwin · surgeftpFeb 27, 2008

  • CVE-2007-4377
    26Monitor

    Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argu

    MediumCVSS 6.0Proof of conceptEPSS 5%

    netwin · surgemailAug 16, 2007

  • cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domain

    MediumCVSS 6.1No exploitEPSS 1%

    netwin · surgeftpDec 29, 2017

  • CVE-2008-7182
    23Monitor

    Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to

    MediumCVSS 4.0Proof of conceptEPSS 24%

    netwin · surgemailSep 8, 2009

  • CVE-2007-3769
    23Monitor

    Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP serv

    MediumCVSS 5.8No exploitEPSS 1%

    netwin · surgeftpJul 15, 2007

  • CVE-2000-0423
    22Monitor

    Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,

    MediumCVSS 5.0Proof of conceptEPSS 8%

    netwin · dnewsMay 5, 2000