Vulnerabilities (CVE)

Filtered by vendor Inter7 Subscribe
Filtered by product Vpopmail
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0990 1 Inter7 1 Vpopmail 2024-02-28 4.6 MEDIUM N/A
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.
CVE-2000-0091 1 Inter7 1 Vpopmail 2024-02-28 10.0 HIGH N/A
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.