{"api_version":"1","generated_at":"2026-07-23T08:52:05+00:00","cve":"CVE-2004-1211","urls":{"html":"https://cve.report/CVE-2004-1211","api":"https://cve.report/api/cve/CVE-2004-1211.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1211","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1211"},"summary":{"title":"CVE-2004-1211","description":"Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-10 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://home.kabelfoon.nl/~jaabogae/han/m_401b.html","name":"http://home.kabelfoon.nl/~jaabogae/han/m_401b.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Han's Mercury (Mail Transport Agent) Information pages.","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/13348","name":"http://secunia.com/advisories/13348","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Mercury Mail Transport System Command Handling Buffer Overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11775","name":"http://www.securityfocus.com/bid/11775","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Mercury Mail Multiple Remote IMAP Stack Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/12508","name":"http://www.osvdb.org/12508","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=110193702909991&w=2","name":"http://marc.info/?l=bugtraq&m=110193702909991&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18318","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18318","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1211","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1211","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1211","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"david_harris","cpe5":"mercury","cpe6":"4.0.1a","cpe7":"*","cpe8":"win32","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:46:12.457Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://home.kabelfoon.nl/~jaabogae/han/m_401b.html"},{"name":"13348","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/13348"},{"name":"20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html"},{"name":"11775","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11775"},{"name":"20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110193702909991&w=2"},{"name":"mercury-command-bo(18318)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18318"},{"name":"12508","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/12508"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-12-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://home.kabelfoon.nl/~jaabogae/han/m_401b.html"},{"name":"13348","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/13348"},{"name":"20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html"},{"name":"11775","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11775"},{"name":"20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110193702909991&w=2"},{"name":"mercury-command-bo(18318)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18318"},{"name":"12508","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/12508"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1211","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://home.kabelfoon.nl/~jaabogae/han/m_401b.html","refsource":"CONFIRM","url":"http://home.kabelfoon.nl/~jaabogae/han/m_401b.html"},{"name":"13348","refsource":"SECUNIA","url":"http://secunia.com/advisories/13348"},{"name":"20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-December/029701.html"},{"name":"11775","refsource":"BID","url":"http://www.securityfocus.com/bid/11775"},{"name":"20041201 Multiple buffer overflows exist in Mercury/32, v4.01a, Dec 8 2003.","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110193702909991&w=2"},{"name":"mercury-command-bo(18318)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18318"},{"name":"12508","refsource":"OSVDB","url":"http://www.osvdb.org/12508"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1211","datePublished":"2004-12-15T05:00:00.000Z","dateReserved":"2004-12-14T00:00:00.000Z","dateUpdated":"2024-08-08T00:46:12.457Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-10 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:david_harris:mercury:4.0.1a:*:win32:*:*:*:*:*","matchCriteriaId":"77BC4009-26EA-4FE1-BEED-915AFBB603D2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1211","Ordinal":"1","Title":"CVE-2004-1211","CVE":"CVE-2004-1211","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1211","Ordinal":"1","NoteData":"Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.","Type":"Description","Title":"CVE-2004-1211"},{"CveYear":"2004","CveId":"1211","Ordinal":"2","NoteData":"2004-12-15","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1211","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}