Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372.
- https://www.exploit-db.com/exploits/4287
No PoCs found on GitHub currently.