VYPR

Vpopmail \(vchkpw\)

by Double Precision Incorporated

CVEs (4)

  • CVE-2000-0091Jan 21, 2000
    risk 0.03cvss epss 0.02

    Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.

  • CVE-2006-2346May 12, 2006
    risk 0.00cvss epss 0.01

    vpopmail 5.4.14 and 5.4.15, with cleartext passwords enabled, allows remote attackers to authenticate to an account that does not have a cleartext password set by using a blank password to (1) SMTP AUTH or (2) APOP.

  • CVE-2001-0990Sep 4, 2001
    risk 0.00cvss epss 0.00

    Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.

  • CVE-2000-0583Jun 30, 2000
    risk 0.00cvss epss 0.01

    vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.