David Harris developed Pegasus Mail and the Mercury mail transport system, a modestly represented suite of email and messaging applications that acquired historical significance in enterprise deployments. Vulnerabilities in this vendor's products center on memory-buffer handling weaknesses and recur across versions of Mercury and its related components, reflecting the parsing demands of mail protocol implementation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by David Harris over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1211HIGH Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary c | Jan 10, 2005 | 10.0 | 85 | NO | YES |
CVE-2005-4411HIGH Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105. | Dec 20, 2005 | 7.5 | 72 | NO | YES |
CVE-2002-1075HIGH Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From | Oct 4, 2002 | 7.5 | 30 | NO | YES |
CVE-2001-0442HIGH Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP com | Jun 27, 2001 | 7.5 | 30 | NO | YES |
CVE-2000-0930MEDIUM Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch. | Dec 19, 2000 | 5.0 | 28 | NO | YES |
CVE-2007-5018MEDIUM Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue mi | Sep 20, 2007 | 6.0 | 25 | NO | YES |
CVE-2000-0931HIGH Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data. | Dec 19, 2000 | 7.5 | 20 | NO | NO |
CVE-2005-4444MEDIUM Stack-based buffer overflow in the trace message functionality in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allow remote attackers to execute arbitrary code via a long POP3 repl | Dec 21, 2005 | 5.1 | 17 | NO | NO |
CVE-2005-4445MEDIUM Off-by-one error in Pegasus Mail 4.21a through 4.21c and 4.30PB1 allows remote attackers to execute arbitrary code via a long email message header, which triggers a one-byte buffer | Dec 21, 2005 | 5.1 | 16 | NO | NO |
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail. | May 15, 1999 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by David Harris.
Media articles that mention a CVE ID that affects a product developed by David Harris — matched by CVE ID, not by vendor name.