The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
📦
messaging_server
Vendor: netscape
Actively Exploited
0
CISA KEV List
PoC / Exploits
2
Code Available
Total RCEs
0
Remote Access
Total CVEs
8
Total Indexed
Avg. EPSS
5.75%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
5.0
CVSS
Severity: MEDIUM
10.0
CVSS
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
Severity: HIGH
5.0
CVSS
CVE-1999-1532
Exploit Found
Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.
Severity: MEDIUM
0.0
CVSS