CVE-2018-25223: Ftnapps Crashmail Ii
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.
Affected products
- Ftnapps Crashmail Ii: up to and including 1.6
Published 2026-03-28. Last modified 2026-10-07.