CVE-2004-1211 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 72.5% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 72.46% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-01-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| david harris | mercury |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mercury/32 Mail Server 4.01a - IMAP RENAME Buffer Overflow (Metasploit) | 2010-05-09 |
| exploit-db | Mercury/32 Mail Server 3.32 < 4.51 - SMTP EIP Overwrite | 2007-08-26 |
| exploit-db | Mercury/32 Mail Server 4.0.1 - 'LOGIN' Remote IMAP Stack Buffer Overflow | 2007-03-24 |
| exploit-db | Mercury/32 Mail Server 4.01a - 'check' Buffer Overflow | 2004-12-01 |
| exploit-db | Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (2) | 2004-12-01 |
| exploit-db | Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (1) | 2004-11-30 |
| exploit-db | Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (3) | 2004-11-29 |
References
- http://home.kabelfoon.nl/~jaabogae/han/m_401b.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html
- http://marc.info/?l=bugtraq&m=110193702909991&w=2
- http://secunia.com/advisories/13348
- http://www.osvdb.org/12508
- http://www.securityfocus.com/bid/11775
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18318
- http://home.kabelfoon.nl/~jaabogae/han/m_401b.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html
- http://marc.info/?l=bugtraq&m=110193702909991&w=2
- http://secunia.com/advisories/13348
- http://www.osvdb.org/12508
- http://www.securityfocus.com/bid/11775
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18318
→ the Explorer · watch your stack · NVD