← Vulnerability feed

Vulnerability record · CVE-2008-1055 · published 27 February 2008

CVE-2008-1055: Netwin surgemail vulnerability

Netwin · Surgemail

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

7.5 CVSS 2.0 High EPSS 7.9% · top 5.5% CWE-134 · CWE-134
7.5CVSS 2.0 base score
7.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1055 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-4372Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is base…EPSS 1.2%10.0CVE-2004-2537Netwin surgemail vulnerabilityUnspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."EPSS 1.7%9.0CVE-2008-1497Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…EPSS 6.3%9.0CVE-2008-1498Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code v…EPSS 7.6%7.5CVE-2007-2655Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string v…EPSS 3.9%6.4CVE-2008-1054Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …EPSS 7.4%6.0CVE-2007-4377Netwin surgemail vulnerabilityStack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to t…EPSS 5.0%5.0CVE-2008-2859Netwin surgemail vulnerabilityUnspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) vi…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2008-1055), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.