Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
References
| Link | Resource |
|---|---|
| http://exploitpack.com | Not Applicable |
| http://ftnapps.sourceforge.net/crashmail.html | Product |
| https://www.exploit-db.com/exploits/44331 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remote-code-execution | Third Party Advisory |
Configurations
History
02 Apr 2026, 19:10
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Ftnapps
Ftnapps crashmail Ii |
|
| References | () http://exploitpack.com - Not Applicable | |
| References | () http://ftnapps.sourceforge.net/crashmail.html - Product | |
| References | () https://www.exploit-db.com/exploits/44331 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remote-code-execution - Third Party Advisory | |
| Summary |
|
|
| CPE | cpe:2.3:a:ftnapps:crashmail_ii:*:*:*:*:*:*:*:* |
28 Mar 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-28 12:16
Updated : 2026-04-02 19:10
NVD link : CVE-2018-25223
Mitre link : CVE-2018-25223
CVE.ORG link : CVE-2018-25223
JSON object : View
Products Affected
ftnapps
- crashmail_ii
CWE
CWE-787
Out-of-bounds Write
