Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.
https://exchange.xforce.ibmcloud.com/vulnerabilities/41402
http://www.securityfocus.com/archive/1/489959/100/0/threaded