CVE-2004-1211
high · 10Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.
10
CVSS
72.5%
EPSS (exploit prob.)
99th
EPSS percentile
2005-01-10
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| david_harris | mercury | 4.0.1a |
Check a specific version with /api/v1/cve/match.
References
- http://home.kabelfoon.nl/~jaabogae/han/m_401b.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html
- http://marc.info/?l=bugtraq&m=110193702909991&w=2
- http://secunia.com/advisories/13348
- http://www.osvdb.org/12508
- http://www.securityfocus.com/bid/11775
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18318
- http://home.kabelfoon.nl/~jaabogae/han/m_401b.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html
- http://marc.info/?l=bugtraq&m=110193702909991&w=2
- http://secunia.com/advisories/13348
- http://www.osvdb.org/12508
- http://www.securityfocus.com/bid/11775
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18318
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-1211