NetWin records
50 published records for vendor netwin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-134 Use of Externally-Controlled Format String2
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
50 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2000-0490Proof of concept | Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN rnetwin · dmail | Critical10.0 | — | 6.2% | Jun 1, 2000 |
41Plan | CVE-2001-1356No exploit | NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote anetwin · surgeftp | Critical10.0 | — | 3.8% | Aug 4, 2001 |
41Plan | CVE-2001-1355No exploit | Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, netwin · dmail | Critical10.0 | — | 3.6% | Jul 20, 2001 |
41Plan | CVE-2004-2537No exploit | Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."netwin · surgemail | Critical10.0 | — | 1.7% | Dec 31, 2004 |
40Plan | CVE-2007-4372No exploit | Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.netwin · surgemail | Critical10.0 | — | 1.2% | Aug 16, 2007 |
38Monitor | CVE-2008-1498Proof of concept | Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitranetwin · surgemail · CWE-119 | Critical9.0 | — | 7.6% | Mar 25, 2008 |
38Monitor | CVE-2008-1497No exploit | Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrarnetwin · surgemail · CWE-119 | Critical9.0 | — | 6.3% | Mar 25, 2008 |
34Monitor | CVE-2007-3768No exploit | The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed responetwin · surgeftp | High8.5 | — | 1.6% | Jul 15, 2007 |
33Monitor | CVE-2004-2254Proof of concept | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration netwin · surgeldap | High7.5 | — | 8.4% | Dec 31, 2004 |
32Monitor | CVE-2008-1055Proof of concept | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote atnetwin · surgemail · CWE-134 | High7.5 | — | 7.9% | Feb 27, 2008 |
31Monitor | CVE-2005-1478No exploit | Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiernetwin · dmail | High7.5 | — | 4.8% | May 11, 2005 |
31Monitor | CVE-2013-4742No exploit | Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary conetwin · surgeftp · CWE-119 | High7.5 | — | 4.3% | Aug 9, 2013 |
31Monitor | CVE-2007-2655No exploit | Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a formatnetwin · surgemail · CWE-134 | High7.5 | — | 3.9% | May 14, 2007 |
31Monitor | CVE-2006-5100Proof of concept | PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arnetwin · webnews | High7.5 | — | 3.8% | Oct 3, 2006 |
31Monitor | CVE-2002-0290No exploit | Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.netwin · webnews | High7.5 | — | 3.3% | May 31, 2002 |
31Monitor | CVE-2000-0422No exploit | Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.netwin · dmail | High7.5 | — | 2.0% | May 4, 2000 |
30Monitor | CVE-2005-1516No exploit | DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog commnetwin · dmail | High7.5 | — | 1.6% | May 11, 2005 |
30Monitor | CVE-2002-0310No exploit | Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whicnetwin · webnews | High7.5 | — | 1.6% | May 31, 2002 |
27Monitor | CVE-2008-1054Proof of concept | Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlnetwin · surgemail · CWE-119 | Medium6.4 | — | 7.4% | Feb 27, 2008 |
27Monitor | CVE-2008-1052Proof of concept | The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vinetwin · surgeftp · CWE-119 | Medium6.4 | — | 6.8% | Feb 27, 2008 |
26Monitor | CVE-2007-4377Proof of concept | Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argunetwin · surgemail | Medium6.0 | — | 5.0% | Aug 16, 2007 |
24Monitor | CVE-2017-17933No exploit | cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainnetwin · surgeftp · CWE-79 | Medium6.1 | — | 0.9% | Dec 29, 2017 |
23Monitor | CVE-2008-7182Proof of concept | Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users tonetwin · surgemail · CWE-119 | Medium4.0 | — | 24.3% | Sep 8, 2009 |
23Monitor | CVE-2007-3769No exploit | Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servnetwin · surgeftp | Medium5.8 | — | 1.2% | Jul 15, 2007 |
22Monitor | CVE-2000-0423Proof of concept | Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,netwin · dnews | Medium5.0 | — | 7.8% | May 5, 2000 |
- CVE-2000-049042Plan
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN r
CriticalCVSS 10.0Proof of conceptEPSS 6%netwin · dmailJun 1, 2000
- CVE-2001-135641Plan
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote a
CriticalCVSS 10.0No exploitEPSS 4%netwin · surgeftpAug 4, 2001
- CVE-2001-135541Plan
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages,
CriticalCVSS 10.0No exploitEPSS 4%netwin · dmailJul 20, 2001
- CVE-2004-253741Plan
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."
CriticalCVSS 10.0No exploitEPSS 2%netwin · surgemailDec 31, 2004
- CVE-2007-437240Plan
Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 1%netwin · surgemailAug 16, 2007
- CVE-2008-149838Monitor
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitra
CriticalCVSS 9.0Proof of conceptEPSS 8%netwin · surgemailMar 25, 2008
- CVE-2008-149738Monitor
Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrar
CriticalCVSS 9.0No exploitEPSS 6%netwin · surgemailMar 25, 2008
- CVE-2007-376834Monitor
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed respo
HighCVSS 8.5No exploitEPSS 2%netwin · surgeftpJul 15, 2007
- CVE-2004-225433Monitor
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration
HighCVSS 7.5Proof of conceptEPSS 8%netwin · surgeldapDec 31, 2004
- CVE-2008-105532Monitor
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote at
HighCVSS 7.5Proof of conceptEPSS 8%netwin · surgemailFeb 27, 2008
- CVE-2005-147831Monitor
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifier
HighCVSS 7.5No exploitEPSS 5%netwin · dmailMay 11, 2005
- CVE-2013-474231Monitor
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co
HighCVSS 7.5No exploitEPSS 4%netwin · surgeftpAug 9, 2013
- CVE-2007-265531Monitor
Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format
HighCVSS 7.5No exploitEPSS 4%netwin · surgemailMay 14, 2007
- CVE-2006-510031Monitor
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute ar
HighCVSS 7.5Proof of conceptEPSS 4%netwin · webnewsOct 3, 2006
- CVE-2002-029031Monitor
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.
HighCVSS 7.5No exploitEPSS 3%netwin · webnewsMay 31, 2002
- CVE-2000-042231Monitor
Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.
HighCVSS 7.5No exploitEPSS 2%netwin · dmailMay 4, 2000
- CVE-2005-151630Monitor
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog comm
HighCVSS 7.5No exploitEPSS 2%netwin · dmailMay 11, 2005
- CVE-2002-031030Monitor
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whic
HighCVSS 7.5No exploitEPSS 2%netwin · webnewsMay 31, 2002
- CVE-2008-105427Monitor
Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earl
MediumCVSS 6.4Proof of conceptEPSS 7%netwin · surgemailFeb 27, 2008
- CVE-2008-105227Monitor
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vi
MediumCVSS 6.4Proof of conceptEPSS 7%netwin · surgeftpFeb 27, 2008
- CVE-2007-437726Monitor
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argu
MediumCVSS 6.0Proof of conceptEPSS 5%netwin · surgemailAug 16, 2007
- CVE-2017-1793324Monitor
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domain
MediumCVSS 6.1No exploitEPSS 1%netwin · surgeftpDec 29, 2017
- CVE-2008-718223Monitor
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to
MediumCVSS 4.0Proof of conceptEPSS 24%netwin · surgemailSep 8, 2009
- CVE-2007-376923Monitor
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP serv
MediumCVSS 5.8No exploitEPSS 1%netwin · surgeftpJul 15, 2007
- CVE-2000-042322Monitor
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,
MediumCVSS 5.0Proof of conceptEPSS 8%netwin · dnewsMay 5, 2000