CVE-2004-1211
David Harris Mercury - Memory Corruption
Title source: ruleDescription
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.
Exploits (8)
exploitdb
WORKING POC
VERIFIED
by Jacopo Cervini · perlremotewindows
https://www.exploit-db.com/exploits/3561
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16484
metasploit
WORKING POC
NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/imap/mercury_rename.rb
References (7)
Scores
EPSS
0.8054
EPSS Percentile
99.1%
Classification
CWE
CWE-119
Status
draft
Affected Products (1)
david_harris/mercury
Timeline
Published
Jan 10, 2005
Tracked Since
Feb 18, 2026