
CVE-2007-1578 – Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
https://notcve.org/view.php?id=CVE-2007-1578
21 Mar 2007 — Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow. Múltiples errores de presencia de signo en entero en la implementación NTLM en Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, con SP4, permite a atacantes remotos ejecutar código de su elección a través del argumento NTLMSSP que dispara un desbordamiento de búfer basado en ... • https://www.exploit-db.com/exploits/3527 •

CVE-2007-1579 – Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
https://notcve.org/view.php?id=CVE-2007-1579
21 Mar 2007 — Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. Un desbordamiento de búfer en la región heap de la memoria en Atrium MERCUR IMAPD, permite a atacantes remotos tener un impacto desconocido por medio de un cierto comando SUBSCRIBE. • https://www.exploit-db.com/exploits/3537 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2006-7038
https://notcve.org/view.php?id=CVE-2006-7038
23 Feb 2007 — Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and (2) certain name service queries that are not properly handled by the SMTP service. Múltiples desbordamientos de búfer en MERCUR Messaging 2005 anterior a Service Pack 4 permite a atacantes remotos provocar denegación de servicio (caida) a través de (1)"lineas de comando en el puerto 32000" y (2) ciertas consulta de nombres de ser... • http://secunia.com/advisories/20432 •

CVE-2006-7039
https://notcve.org/view.php?id=CVE-2006-7039
23 Feb 2007 — The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field. El servicio IMAP4 en MERCUR Messaging 2005 anterior a Service Pack 4 permite a atacantes remotos provocar denegación de servicio (caida) a través de un mensaje con un campo subject. • http://secunia.com/advisories/20432 •

CVE-2006-7040
https://notcve.org/view.php?id=CVE-2006-7040
23 Feb 2007 — Unspecified vulnerability in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a TOP command to the POP3 service. Vulnerabilidad no especificada en MERCUR Messaging 2005 anterior a Service Pack 4 permite a atacantes remotos provocar denegación de servicio (caida) a través del comando TOP en el servicio POP3. • http://secunia.com/advisories/20432 •

CVE-2006-7041
https://notcve.org/view.php?id=CVE-2006-7041
23 Feb 2007 — The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known. El servicio SMTP en MERCUR Messaging 2005 anterior a Service Pack 4 permite a atacantes remotos provocar denegación de servicio (bucle infinito) a través de un mensaje en el cual ni saben al autor ni la dirección receptora. • http://secunia.com/advisories/20432 •

CVE-2003-1177 – Atrium Software Mercur MailServer 3.3/4.0/4.2 - IMAP AUTH Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-2003-1177
31 Dec 2003 — Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) AUTH command to the POP3 server or (2) AUTHENTICATE command to the IMAP server. • https://www.exploit-db.com/exploits/23267 •

CVE-2003-1322
https://notcve.org/view.php?id=CVE-2003-1322
31 Dec 2003 — Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELETE, (3) SUBSCRIBE, (4) RENAME, (5) UNSUBSCRIBE, (6) LIST, (7) LSUB, (8) STATUS, (9) LOGIN, (10) CREATE, or (11) SELECT command. • http://www.iss.net/security_center/static/12203.php •

CVE-2002-1073 – 3.3/4.0/4.2 MERCUR MailServer - Control-Service Buffer Overflow
https://notcve.org/view.php?id=CVE-2002-1073
31 Aug 2002 — Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password. • https://www.exploit-db.com/exploits/21626 •

CVE-2001-0280 – Atrium Software Mercur Mail Server 3.3 - EXPN Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-0280
03 May 2001 — Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command. • https://www.exploit-db.com/exploits/20647 •