David HarrisCVEs & Vulnerabilities

10 CVEs affecting David Harris products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

pegasus mail 12mercury nlm 3mercury 1mercury 32 1mercury mail transport system 1
CVE-2007-5018MEDIUMpoc

Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.

21 Sep 2007
6.0
CVSS
CVE-2005-4445MEDIUM

Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows remote attackers to execute arbitrary code via a long email message header, which triggers a one-byte buffer overflow.

21 Dec 2005
5.1
CVSS
CVE-2005-4444MEDIUM

Stack-based buffer overflow in the trace message functionality in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allow remote attackers to execute arbitrary code via a long POP3 reply.

21 Dec 2005
5.1
CVSS
CVE-2005-4411HIGHpoc

Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.

20 Dec 2005
7.5
CVSS
CVE-2004-1211CRITICALpoc

Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

10 Jan 2005
10.0
CVSS
CVE-2002-1075HIGHpoc

Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.

4 Oct 2002
7.5
CVSS
CVE-2001-0442HIGHpoc

Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.

27 Jun 2001
7.5
CVSS
CVE-2000-0930MEDIUMpoc

Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.

19 Dec 2000
5.0
CVSS
CVE-2000-0931HIGH

Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.

19 Dec 2000
7.5
CVSS
CVE-1999-1366LOW

Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.

15 May 1999
3.6
CVSS
← PrevPage 1 / 1Next →