Known Vulnerabilities for products from Netwin

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Netwin".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2017-17933 json cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the ... 6.1 - MEDIUM 2017-12-29 2021-09-10
CVE-2013-4742 json Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execu... 7.5 - HIGH 2013-08-09 2017-08-29
CVE-2012-2575 json Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 6.0a4 allows remote attackers to inject arbitrary web script or ... 4.3 - MEDIUM 2012-09-17 2012-09-18
CVE-2010-3201 json Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web scri... 4.3 - MEDIUM 2011-01-07 2018-10-10
CVE-2010-1068 json Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inj... 4.3 - MEDIUM 2010-03-23 2017-08-17
CVE-2008-7182 json Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authent... Not Provided 2009-09-08 2026-04-23
CVE-2008-5421 json The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (h... Not Provided 2008-12-11 2026-04-23
CVE-2008-2859 json Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of s... Not Provided 2008-06-25 2026-04-23
CVE-2008-1498 json Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to ... Not Provided 2008-03-25 2026-04-23
CVE-2008-1497 json Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to e... Not Provided 2008-03-25 2026-04-23
CVE-2008-1055 json Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, a... Not Provided 2008-02-27 2026-04-23
CVE-2008-1054 json Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMai... Not Provided 2008-02-27 2026-04-23
CVE-2008-1052 json The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (d... Not Provided 2008-02-27 2026-04-23
CVE-2007-6457 json Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of service (cr... Not Provided 2007-12-20 2026-04-23
CVE-2007-5370 json Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow... Not Provided 2007-10-11 2026-04-23
CVE-2007-4377 json Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code ... Not Provided 2007-08-16 2026-04-23
CVE-2007-4372 json Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE:... Not Provided 2007-08-16 2026-04-23
CVE-2007-3769 json Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, ... Not Provided 2007-07-15 2026-04-23
CVE-2007-3768 json The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a ... Not Provided 2007-07-15 2026-04-23
CVE-2007-2655 json Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, po... Not Provided 2007-05-14 2026-04-23

Known software with vulnerabilities from Netwin

Type Vendor Product Version
ApplicationNetwinSurgeftp1.1h