Pmail develops a focused line of mail transport and client products, including Mercury Mail Transport System and Pegasus Mail, that serve small to medium deployments and legacy environments. The vendor's vulnerability profile centers on memory-buffer handling and input-validation weaknesses characteristic of long-lived mail infrastructure, and public exploit code has been developed for disclosed flaws in this product family. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pmail over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1373HIGH Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: t | Mar 10, 2007 | 10.0 | 75 | NO | YES |
CVE-2007-4440HIGH Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AU | Aug 21, 2007 | 7.5 | 72 | NO | YES |
CVE-2004-2513HIGH Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command. | Dec 31, 2004 | 10.0 | 39 | NO | YES |
CVE-2009-3838HIGH Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary | Nov 2, 2009 | 9.3 | 37 | NO | YES |
CVE-1999-0098HIGH Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities. | Apr 1, 1998 | 10.0 | 28 | NO | NO |
CVE-2017-9046HIGH winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the deskto | May 21, 2017 | 7.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pmail.
Media articles that mention a CVE ID that affects a product developed by Pmail — matched by CVE ID, not by vendor name.