CVE-2007-4440
MercuryS SMTP <4.51 - Buffer Overflow
Title source: llmDescription
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
Exploits (4)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16821
exploitdb
WORKING POC
VERIFIED
by ZhenHan.Liu · c++remotewindows
https://www.exploit-db.com/exploits/4301
exploitdb
WORKING POC
VERIFIED
by eliteboy · perldoswindows
https://www.exploit-db.com/exploits/4294
metasploit
WORKING POC
GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/smtp/mercury_cram_md5.rb
References (9)
Scores
EPSS
0.8272
EPSS Percentile
99.2%
Details
CWE
CWE-119
Status
published
Products (1)
pmail/mercury_mail_transport_system
< 4.51
Published
Aug 21, 2007
Tracked Since
Feb 18, 2026