CVE-2004-1211

David Harris Mercury - Memory Corruption

Title source: rule

Description

Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

Exploits (8)

exploitdb WORKING POC VERIFIED
by Jacopo Cervini · perlremotewindows
https://www.exploit-db.com/exploits/3561
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16484
metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/imap/mercury_rename.rb
exploitdb WORKING POC
pythonremotewindows
https://www.exploit-db.com/exploits/663
exploitdb WORKING POC
perldoswindows
https://www.exploit-db.com/exploits/1159
exploitdb WORKING POC
cremotewindows
https://www.exploit-db.com/exploits/670
exploitdb WORKING POC
cremotewindows
https://www.exploit-db.com/exploits/668
exploitdb WORKING POC
cppremotewindows
https://www.exploit-db.com/exploits/4316

Scores

EPSS 0.8054
EPSS Percentile 99.1%

Classification

CWE
CWE-119
Status draft

Affected Products (1)

david_harris/mercury

Timeline

Published Jan 10, 2005
Tracked Since Feb 18, 2026