// For flags

CVE-2007-5018

Mercury/32 4.52 IMAPD - 'SEARCH' (Authenticated) Overflow

Severity Score

6.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.

Desbordamiento de búfer basado en pila en el IMAPD del Mercury/32 4.52 permite a usuarios remotos autenticados ejecutar código de su elección a través de un argumento largo en el comando SEARCH ON. NOTA: esta vulnerabilidad puede solaparse con la CVE-2004-1211.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-09-20 CVE Reserved
  • 2007-09-20 CVE Published
  • 2024-06-16 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
David Harris
Search vendor "David Harris"
Mercury 32
Search vendor "David Harris" for product "Mercury 32"
4.5.2
Search vendor "David Harris" for product "Mercury 32" and version "4.5.2"
-
Affected