Unrated severityNVD Advisory· Published Aug 21, 2007· Updated Apr 23, 2026
CVE-2007-4440
CVE-2007-4440
Description
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
Affected products
1- cpe:2.3:a:pmail:mercury_mail_transport_system:*:*:*:*:*:*:*:*Range: <=4.51
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.securityfocus.com/bid/25357nvdExploit
- secunia.com/advisories/26519nvdVendor Advisory
- www.vupen.com/english/advisories/2007/2918nvdVendor Advisory
- archives.neohapsis.com/archives/fulldisclosure/2007-08/0341.htmlnvd
- www.pmail.com/m32_451.htmnvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36117nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36299nvd
- www.exploit-db.com/exploits/4294nvd
News mentions
0No linked articles in our index yet.