Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372.
https://www.exploit-db.com/exploits/4287
https://exchange.xforce.ibmcloud.com/vulnerabilities/36009
http://www.vupen.com/english/advisories/2007/2875
http://www.securityfocus.com/bid/25318