Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-28 12:16
Updated : 2026-03-30 13:26
NVD link : CVE-2018-25223
Mitre link : CVE-2018-25223
CVE.ORG link : CVE-2018-25223
JSON object : View
Products Affected
No product.
CWE
CWE-787
Out-of-bounds Write
