Atrium Software's vulnerability footprint centers on a narrow line of legacy messaging and mail server products, including Mercur MailServer and its associated IMAP and POP3 components, which were widely deployed in enterprise email infrastructure. The exposure recurs through memory-safety and bounds-checking weaknesses characteristic of native messaging services, and vulnerabilities associated with this vendor frequently acquire public exploit code. Defenders managing legacy Atrium deployments should prioritize inventory and lifecycle planning; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Atrium Software over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1579HIGH Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. | Mar 21, 2007 | 10.0 | 66 | NO | YES |
CVE-2007-1578HIGH Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long N | Mar 21, 2007 | 10.0 | 43 | NO | YES |
CVE-2001-0280HIGH Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command. | May 3, 2001 | 10.0 | 41 | NO | YES |
CVE-2003-1177HIGH Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) A | Dec 31, 2003 | 7.5 | 40 | NO | YES |
CVE-2002-1073HIGH Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password. | Oct 4, 2002 | 7.5 | 36 | NO | YES |
CVE-2003-1322HIGH Multiple stack-based buffer overflows in Atrium MERCUR IMAPD in MERCUR Mailserver before 4.2.15.0 allow remote attackers to execute arbitrary code via a long (1) EXAMINE, (2) DELET | Dec 31, 2003 | 10.0 | 26 | NO | NO |
CVE-2000-0198MEDIUM Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service. | Mar 15, 2000 | 5.0 | 25 | NO | YES |
CVE-2000-0341MEDIUM ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name. | May 1, 2000 | 5.0 | 24 | NO | YES |
CVE-2000-0239MEDIUM Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request. | Mar 15, 2000 | 5.0 | 23 | NO | YES |
CVE-2006-7038HIGH Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and | Feb 23, 2007 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Atrium Software.
Media articles that mention a CVE ID that affects a product developed by Atrium Software — matched by CVE ID, not by vendor name.