{"api_version":"1","generated_at":"2026-04-25T00:30:50+00:00","cve":"CVE-2000-0960","urls":{"html":"https://cve.report/CVE-2000-0960","api":"https://cve.report/api/cve/CVE-2000-0960.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2000-0960","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2000-0960"},"summary":{"title":"CVE-2000-0960","description":"The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.","state":"PUBLISHED","assigner":"mitre","published_at":"2000-12-19 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/1787","name":"http://www.securityfocus.com/bid/1787","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Netscape Messaging Server Email Address Verification Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=97138100426121&w=2","name":"http://marc.info/?l=bugtraq&m=97138100426121&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Netscape Messaging server 4.15 poor error strings' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5364","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5364","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2000-0960","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2000-0960","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2000","cve_id":"960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netscape","cpe5":"messaging_server","cpe6":"4.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2000","cve_id":"960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netscape","cpe5":"messaging_server","cpe6":"4.15","cpe7":"patch1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2000","cve_id":"960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netscape","cpe5":"messaging_server","cpe6":"4.15","cpe7":"patch2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T05:37:31.635Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1787","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/1787"},{"name":"20001011 Netscape Messaging server 4.15 poor error strings","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=97138100426121&w=2"},{"name":"netscape-messaging-email-verify(5364)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5364"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2000-10-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-11-02T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1787","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/1787"},{"name":"20001011 Netscape Messaging server 4.15 poor error strings","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=97138100426121&w=2"},{"name":"netscape-messaging-email-verify(5364)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5364"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2000-0960","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1787","refsource":"BID","url":"http://www.securityfocus.com/bid/1787"},{"name":"20001011 Netscape Messaging server 4.15 poor error strings","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=97138100426121&w=2"},{"name":"netscape-messaging-email-verify(5364)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/5364"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2000-0960","datePublished":"2001-01-22T05:00:00.000Z","dateReserved":"2000-11-24T00:00:00.000Z","dateUpdated":"2024-08-08T05:37:31.635Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2000-12-19 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netscape:messaging_server:4.15:*:*:*:*:*:*:*","matchCriteriaId":"294BA50A-A19B-46F8-8D9E-4F0DA98F74E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:netscape:messaging_server:4.15:patch1:*:*:*:*:*:*","matchCriteriaId":"41AD2442-625E-4654-8654-0BF345FAC3B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:netscape:messaging_server:4.15:patch2:*:*:*:*:*:*","matchCriteriaId":"32228CBD-0C64-40B9-85A8-6925FDEEC89F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2000","CveId":"960","Ordinal":"1","Title":"CVE-2000-0960","CVE":"CVE-2000-0960","Year":"2000"},"notes":[{"CveYear":"2000","CveId":"960","Ordinal":"1","NoteData":"The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.","Type":"Description","Title":"CVE-2000-0960"},{"CveYear":"2000","CveId":"960","Ordinal":"2","NoteData":"2001-01-22","Type":"Other","Title":"Published"},{"CveYear":"2000","CveId":"960","Ordinal":"3","NoteData":"2005-11-02","Type":"Other","Title":"Modified"}]}}}