pmail records
6 published records for vendor pmail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 33.3%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2007-1373Weaponized | Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrarypmail · mercury mail transport system | Critical10.0 | — | 58.7% | Mar 9, 2007 |
49Plan | CVE-2007-4440Weaponized | Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackerspmail · mercury mail transport system · CWE-119 | High7.5 | — | 64.5% | Aug 20, 2007 |
43Plan | CVE-2004-2513Proof of concept | Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT commapmail · pegasus | Critical10.0 | — | 9.8% | Dec 31, 2004 |
41Plan | CVE-1999-0098No exploit | Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.apple · appleshare | Critical10.0 | — | 3.1% | Apr 1, 1998 |
39Monitor | CVE-2009-3838Proof of concept | Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (applicatpmail · pegasus mail · CWE-119 | Critical9.3 | — | 6.2% | Nov 2, 2009 |
29Monitor | CVE-2017-9046No exploit | winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally.pmail · pegasus · CWE-20 | High7.3 | — | 0.6% | May 21, 2017 |
- CVE-2007-137358Plan
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary
CriticalCVSS 10.0WeaponizedEPSS 59%pmail · mercury mail transport systemMar 9, 2007
- CVE-2007-444049Plan
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers
HighCVSS 7.5WeaponizedEPSS 65%pmail · mercury mail transport systemAug 20, 2007
- CVE-2004-251343Plan
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT comma
CriticalCVSS 10.0Proof of conceptEPSS 10%pmail · pegasusDec 31, 2004
- CVE-1999-009841Plan
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.
CriticalCVSS 10.0No exploitEPSS 3%apple · appleshareApr 1, 1998
- CVE-2009-383839Monitor
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (applicat
CriticalCVSS 9.3Proof of conceptEPSS 6%pmail · pegasus mailNov 2, 2009
- CVE-2017-904629Monitor
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally.
HighCVSS 7.3No exploitEPSS 1%pmail · pegasusMay 21, 2017