VYPR
Unrated severityNVD Advisory· Published Dec 19, 2000· Updated Apr 16, 2026

CVE-2000-0960

CVE-2000-0960

Description

The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.

Affected products

3
  • cpe:2.3:a:netscape:messaging_server:4.15:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:netscape:messaging_server:4.15:*:*:*:*:*:*:*
    • cpe:2.3:a:netscape:messaging_server:4.15:patch1:*:*:*:*:*:*
    • cpe:2.3:a:netscape:messaging_server:4.15:patch2:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.