Unrated severityNVD Advisory· Published Feb 27, 2008· Updated Apr 23, 2026
CVE-2008-1055
CVE-2008-1055
Description
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.
Affected products
25cpe:2.3:a:netwin:surgemail:2.1c7:*:*:*:*:*:*:*+ 23 more
- cpe:2.3:a:netwin:surgemail:2.1c7:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.2a6:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.2c9:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:*:*:*:*:*:*:*:*range: <=38k4
- cpe:2.3:a:netwin:surgemail:1.8a:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8b3:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8d:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8e:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.8g3:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:1.9b2:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.0a2:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.0c:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.0e:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.0g2:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.1a:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.2c10:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.2g2:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:2.2g3:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:3.0a:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:3.0c2:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:3.8f3:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:39a:*:*:*:*:*:*:*
- cpe:2.3:a:netwin:surgemail:beta_39a:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/27990nvdExploit
- secunia.com/advisories/29105nvdVendor Advisory
- aluigi.altervista.org/adv/surgemailz-adv.txtnvd
- secunia.com/advisories/29137nvd
- securityreason.com/securityalert/3705nvd
- www.securityfocus.com/archive/1/488741/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/0678nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/40833nvd
News mentions
0No linked articles in our index yet.