VendorsAtrium Softwaremercur_mailserverall versions
Vulnerabilities

Atrium Software Mercur Mailserver

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2003-1322
Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command.
Published 2007-03-21 · Modified
10.0EPSS 0.057
CVE-2003-1177
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server.
Published 2005-05-10 · Modified
7.51 PoCEPSS 0.129
CVE-2002-1073
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.
Published 2002-08-31 · Modified
7.51 PoCEPSS 0.057
CVE-2000-0318
Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.
Published 2000-10-13 · Modified
7.5EPSS 0.012
CVE-2000-0198
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service.
Published 2000-03-22 · Modified
5.02 PoCEPSS 0.084
CVE-2000-0239
Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.
Published 2000-04-12 · Modified
5.01 PoCEPSS 0.036