← Vulnerability feed

Vulnerability record · CVE-2008-7182 · published 8 September 2009

CVE-2008-7182: Netwin surgemail memory buffer overflow vulnerability

Netwin · Surgemail

Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.

4.0 CVSS 2.0 Medium EPSS 24% · top 2.2% CWE-119 · Memory buffer overflow
4.0CVSS 2.0 base score
24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.

AV:N/AC:L/Au:S/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-7182 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-4372Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is base…EPSS 1.2%10.0CVE-2004-2537Netwin surgemail vulnerabilityUnspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."EPSS 1.7%9.0CVE-2008-1497Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code vi…EPSS 6.3%9.0CVE-2008-1498Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code v…EPSS 7.6%7.5CVE-2008-1055Netwin surgemail vulnerabilityFormat string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers t…EPSS 7.9%7.5CVE-2007-2655Netwin surgemail vulnerabilityUnspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string v…EPSS 3.9%6.4CVE-2008-1054Netwin surgemail memory buffer overflow vulnerabilityStack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and …EPSS 7.4%6.0CVE-2007-4377Netwin surgemail vulnerabilityStack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to t…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2008-7182), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.