VYPR
Unrated severityNVD Advisory· Published Dec 31, 1999· Updated Apr 16, 2026

CVE-1999-1074

CVE-1999-1074

Description

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

Affected products

9
  • Webmin/Webmin9 versions
    cpe:2.3:a:webmin:webmin:0.1:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:webmin:webmin:0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.21:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.22:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.31:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.41:*:*:*:*:*:*:*
    • cpe:2.3:a:webmin:webmin:0.42:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.