Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Atrium Software

First CVE: Mar 15, 2000Active for: 26 yearsTotal CVEs: 14
55.0
VTI Score
TOP TARGET

Atrium Software's vulnerability footprint centers on a narrow line of legacy messaging and mail server products, including Mercur MailServer and its associated IMAP and POP3 components, which were widely deployed in enterprise email infrastructure. The exposure recurs through memory-safety and bounds-checking weaknesses characteristic of native messaging services, and vulnerabilities associated with this vendor frequently acquire public exploit code. Defenders managing legacy Atrium deployments should prioritize inventory and lifecycle planning; current severity, exploitation, and exposure details are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Atrium Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2000
26 years ago
Most Recent CVE
Mar 21, 2007
7,066 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-1579HIGH
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command.
Mar 21, 200710.066NOYES
CVE-2007-1578HIGH
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long N
Mar 21, 200710.043NOYES
CVE-2001-0280HIGH
Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.
May 3, 200110.041NOYES
CVE-2003-1177HIGH
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) A
Dec 31, 20037.540NOYES
CVE-2002-1073HIGH
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.
Oct 4, 20027.536NOYES
CVE-2003-1322HIGH
Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELET
Dec 31, 200310.026NONO
CVE-2000-0198MEDIUM
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service.
Mar 15, 20005.025NOYES
CVE-2000-0341MEDIUM
ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.
May 1, 20005.024NOYES
CVE-2000-0239MEDIUM
Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.
Mar 15, 20005.023NOYES
CVE-2006-7038HIGH
Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and
Feb 23, 20077.820NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
29%
71%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
57.1% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Atrium Software.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Atrium Software — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Atrium Software's Products

View all 1 CNAs →

Top CWEs