CVE-2018-25223

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ftnapps:crashmail_ii:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:10

Type Values Removed Values Added
First Time Ftnapps
Ftnapps crashmail Ii
References () http://exploitpack.com - () http://exploitpack.com - Not Applicable
References () http://ftnapps.sourceforge.net/crashmail.html - () http://ftnapps.sourceforge.net/crashmail.html - Product
References () https://www.exploit-db.com/exploits/44331 - () https://www.exploit-db.com/exploits/44331 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remote-code-execution - () https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remote-code-execution - Third Party Advisory
Summary
  • (es) Crashmail 1.6 contiene una vulnerabilidad de desbordamiento de búfer basado en pila que permite a atacantes remotos ejecutar código arbitrario enviando entrada maliciosa a la aplicación. Los atacantes pueden crear cargas útiles con cadenas ROP para lograr la ejecución de código en el contexto de la aplicación, con intentos fallidos que pueden causar denegación de servicio.
CPE cpe:2.3:a:ftnapps:crashmail_ii:*:*:*:*:*:*:*:*

28 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-28 12:16

Updated : 2026-04-02 19:10


NVD link : CVE-2018-25223

Mitre link : CVE-2018-25223

CVE.ORG link : CVE-2018-25223


JSON object : View

Products Affected

ftnapps

  • crashmail_ii
CWE
CWE-787

Out-of-bounds Write