Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pmail

First CVE: Apr 1, 1998Active for: 28 yearsTotal CVEs: 6

Pmail develops a focused line of mail transport and client products, including Mercury Mail Transport System and Pegasus Mail, that serve small to medium deployments and legacy environments. The vendor's vulnerability profile centers on memory-buffer handling and input-validation weaknesses characteristic of long-lived mail infrastructure, and public exploit code has been developed for disclosed flaws in this product family. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pmail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 1998
28 years ago
Most Recent CVE
May 21, 2017
3,351 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-1373HIGH
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: t
Mar 10, 200710.075NOYES
CVE-2007-4440HIGH
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AU
Aug 21, 20077.572NOYES
CVE-2004-2513HIGH
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.
Dec 31, 200410.039NOYES
CVE-2009-3838HIGH
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary
Nov 2, 20099.337NOYES
CVE-1999-0098HIGH
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.
Apr 1, 199810.028NONO
CVE-2017-9046HIGH
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the deskto
May 21, 20177.325NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local1 (16.7%)
Network0 (0.0%)
Unknown5 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (16.7%)
High0 (0.0%)
Unknown5 (83.3%)
User Interaction
None0 (0.0%)
Unknown5 (83.3%)
Required1 (16.7%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (83.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
33.3% of CVEs· 99th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
66.7% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pmail.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pmail — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pmail's Products

View all 1 CNAs →

Top CWEs