---
id: CVE-2018-25223
title: Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution
summary: >-
  Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows
  remote attackers to execute arbitrary code by sending malicious input to the
  application. Attackers can craft payloads with ROP chains to achieve code
  executi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-787
vendor: crashmail
product: Crashmail
affected:
  - Crashmail 1.6
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-04-01T14:03:21.930439Z'
exploitAvailable: true
published: '2026-03-28'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T21:44:51.447Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2018-25223'
references:
  - url: 'https://www.exploit-db.com/exploits/44331'
    label: ExploitDB-44331
  - url: 'http://ftnapps.sourceforge.net/crashmail.html'
    label: Official Product Homepage
  - url: 'http://exploitpack.com'
    label: Official Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/crashmail-stack-based-buffer-overflow-remote-code-execution
    label: >-
      VulnCheck Advisory: Crashmail 1.6 Stack-based Buffer Overflow Remote Code
      Execution
tags:
  - cve.org
  - exploit-available
epss: 0.00884
epssPercentile: 0.57741
ingestedAt: '2026-10-01T23:03:32.846Z'
---

## Overview

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

## Affected

- `Crashmail 1.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
