← Vulnerability feed

Vulnerability record · CVE-2007-2655 · published 14 May 2007

CVE-2007-2655: Netwin surgemail vulnerability

Netwin · Surgemail

Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.

7.5 CVSS 2.0 High EPSS 3.9% · top 10.1% CWE-134 · CWE-134
7.5CVSS 2.0 base score
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2655 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-4372Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is base…EPSS 1.2%10.0CVE-2004-2537Netwin surgemail vulnerabilityUnspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."EPSS 1.7%9.0CVE-2008-1497Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…EPSS 6.3%9.0CVE-2008-1498Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code v…EPSS 7.6%7.5CVE-2008-1055Netwin surgemail vulnerabilityFormat string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers t…EPSS 7.9%6.4CVE-2008-1054Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …EPSS 7.4%6.0CVE-2007-4377Netwin surgemail vulnerabilityStack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to t…EPSS 5.0%5.0CVE-2008-2859Netwin surgemail vulnerabilityUnspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) vi…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2007-2655), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.