← Vulnerability feed

Vulnerability record · CVE-2007-4377 · published 16 August 2007

CVE-2007-4377: Netwin surgemail vulnerability

Netwin · Surgemail

Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372.

6.0 CVSS 2.0 Medium EPSS 5.0% · top 8.0%
6.0CVSS 2.0 base score
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372.

AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4377 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-4372Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is base…EPSS 1.2%10.0CVE-2004-2537Netwin surgemail vulnerabilityUnspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."EPSS 1.7%9.0CVE-2008-1497Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…EPSS 6.3%9.0CVE-2008-1498Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code v…EPSS 7.6%7.5CVE-2008-1055Netwin surgemail vulnerabilityFormat string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers t…EPSS 7.9%7.5CVE-2007-2655Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string v…EPSS 3.9%6.4CVE-2008-1054Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …EPSS 7.4%5.0CVE-2008-2859Netwin surgemail vulnerabilityUnspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) vi…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2007-4377), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.