CVE-2018-25223

Severity CVSS v4.0:
CRITICAL
Type:
CWE-787 Out-of-bounds Write
Publication date:
28/03/2026
Last modified:
02/04/2026

Description

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ftnapps:crashmail_ii:*:*:*:*:*:*:*:* 1.6 (including)