CVE Vulnerabilities

CVE-2002-1416

Published: Apr 11, 2003 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.

Affected Software

Name Vendor Start Version End Version
Webeasymail Webeasymail * 3.4.2.2 (including)

References