CVE-2008-2859
UnknownEPSS 3.38%
Last modified
CVE-2008-2859 is a vulnerability of currently unknown severity. Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command.". EPSS estimates a 3.38% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netwin | Surgemail | <= 3.9g |
| Netwin | Surgemail | 3.8a |
| Netwin | Surgemail | 3.8b |
| Netwin | Surgemail | 3.8d |
| Netwin | Surgemail | 3.8f |
| Netwin | Surgemail | 3.8f2 |
| Netwin | Surgemail | 3.8f3 |
| Netwin | Surgemail | 3.8i |
| Netwin | Surgemail | 3.8i2 |
| Netwin | Surgemail | 3.8i3 |
| Netwin | Surgemail | 3.8k |
| Netwin | Surgemail | 3.8k2 |
| Netwin | Surgemail | 3.8k3 |
| Netwin | Surgemail | 3.8k4 |
| Netwin | Surgemail | 3.8m |
| Netwin | Surgemail | 3.8o |
| Netwin | Surgemail | 3.8q |
| Netwin | Surgemail | 3.8s |
| Netwin | Surgemail | 3.8u |
| Netwin | Surgemail | 3.9a |
| Netwin | Surgemail | 3.9c |
| Netwin | Surgemail | 3.9e |
References
- http://secunia.com/advisories/30739Vendor Advisory
- http://secunia.com/advisories/30739Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2859?
Unspecified vulnerability in the IMAP service in NetWin SurgeMail before 3.9g2 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors related to an "imap command."
How severe is CVE-2008-2859?
Severity scoring for CVE-2008-2859 is pending analysis. The EPSS model estimates a 3.38% probability of exploitation in the next 30 days.
How do I fix CVE-2008-2859?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2853SQL injection vulnerability in index.php in Easy Webstore 1.…
- CVE-2008-2854Multiple PHP remote file inclusion vulnerabilities in Orland…
- CVE-2008-2855Cross-site scripting (XSS) vulnerability in clanek.php in Ow…
- CVE-2008-2856SQL injection vulnerability in clanek.php in OwnRS Beta 3 al…
- CVE-2008-2857AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cle…
- CVE-2008-2858SQL injection vulnerability in index.php in WebChamado 1.1 a…
- CVE-2008-2860SQL injection vulnerability in category.php in AJSquare AJ A…
- CVE-2008-2861Multiple cross-site scripting (XSS) vulnerabilities in eLine…
- CVE-2008-2862Multiple SQL injection vulnerabilities in eLineStudio Site C…
- CVE-2008-2863Multiple absolute path traversal vulnerabilities in eLineStu…
- CVE-2008-2864eLineStudio Site Composer (ESC) 2.6 and earlier allows remot…
- CVE-2008-2865SQL injection vulnerability in index.php in Kalptaru Infotec…
Are you affected by CVE-2008-2859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
