CVE-2007-4440

MercuryS SMTP <4.51 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16821
exploitdb WORKING POC VERIFIED
by ZhenHan.Liu · c++remotewindows
https://www.exploit-db.com/exploits/4301
exploitdb WORKING POC VERIFIED
by eliteboy · perldoswindows
https://www.exploit-db.com/exploits/4294
metasploit WORKING POC GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/smtp/mercury_cram_md5.rb

Scores

EPSS 0.8272
EPSS Percentile 99.2%

Details

CWE
CWE-119
Status published
Products (1)
pmail/mercury_mail_transport_system < 4.51
Published Aug 21, 2007
Tracked Since Feb 18, 2026