CVE-2018-25223
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Mar 28, 2026
Vendor
unknown
Description
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.