Mercur operates a focused messaging platform with a modest vulnerability footprint centered on its mail and collaboration product line. The observed weakness classes lack granular specificity in available disclosure data, underscoring the small scale of this vendor's documented CVE history; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mercur over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1255HIGH Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execut | Mar 19, 2006 | 10.0 | 79 | NO | YES |
CVE-2005-1657HIGH Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefo | May 18, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-1656MEDIUM Mercur Messaging 2005 SP2 allows remote attackers to read the source code of .ctml files via a URL with a trailing hex-encoded space ("%20"). | May 18, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mercur.
Media articles that mention a CVE ID that affects a product developed by Mercur — matched by CVE ID, not by vendor name.