CVE-2001-0990
https://notcve.org/view.php?id=CVE-2001-0990
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library. • http://www.inter7.com/vpopmail/ChangeLog http://www.securityfocus.com/archive/1/212036 http://www.securityfocus.com/bid/3284 https://exchange.xforce.ibmcloud.com/vulnerabilities/7076 •
CVE-2000-0583
https://notcve.org/view.php?id=CVE-2000-0583
vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives. • http://www.securityfocus.com/bid/1418 http://www.securityfocus.com/templates/archive.pike?list=1&msg=395BD2A8.5D3396A7%40secureaustin.com http://www.vpopmail.cx/vpopmail-ChangeLog •
CVE-2000-0091 – Inter7 vpopmail (vchkpw) 3.4.11 - Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2000-0091
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. • https://www.exploit-db.com/exploits/19727 http://www.inter7.com/vpopmail http://www.inter7.com/vpopmail/ChangeLog http://www.securityfocus.com/bid/942 •