Filtered by vendor Netwin
Subscriptions
Total
52 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2004-2537 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A |
| Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug." | ||||
| CVE-2005-0845 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A |
| Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter. | ||||
| CVE-2005-0846 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field. | ||||
| CVE-2005-1034 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A |
| SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command. | ||||
| CVE-2005-1478 | 1 Netwin | 1 Dmail | 2025-04-03 | N/A |
| Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command. | ||||
| CVE-2000-0490 | 1 Netwin | 1 Dmail | 2025-04-03 | N/A |
| Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request. | ||||
| CVE-2000-0782 | 1 Netwin | 1 Netauth | 2025-04-03 | N/A |
| netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | ||||
| CVE-2001-0696 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A |
| NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. | ||||
| CVE-2001-0698 | 1 Netwin | 1 Surgeftp | 2025-04-03 | N/A |
| Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. | ||||
| CVE-2002-0310 | 1 Netwin | 1 Webnews | 2025-04-03 | N/A |
| Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879. | ||||
| CVE-2005-1516 | 1 Netwin | 1 Dmail | 2025-04-03 | N/A |
| DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function. | ||||
| CVE-2005-1714 | 1 Netwin | 1 Surgemail | 2025-04-03 | N/A |
| Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | ||||