{"api_version":"1","generated_at":"2026-07-23T11:46:48+00:00","cve":"CVE-2002-1416","urls":{"html":"https://cve.report/CVE-2002-1416","api":"https://cve.report/api/cve/CVE-2002-1416.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1416","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1416"},"summary":{"title":"CVE-2002-1416","description":"The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-04-11 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.iss.net/security_center/static/9925.php","name":"http://www.iss.net/security_center/static/9925.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: webeasymail-pop3-bruteforce (9925): WebEasyMail POP3 username/password brute force attack","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://online.securityfocus.com/archive/1/288222","name":"http://online.securityfocus.com/archive/1/288222","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"SecurityFocus HOME Mailing List: BugTraq","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/5519","name":"http://www.securityfocus.com/bid/5519","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1416","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1416","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1416","vulnerable":"1","versionEndIncluding":"3.4.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webeasymail","cpe5":"webeasymail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:26:27.339Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020820 Advisory: DoS in WebEasyMail +more possible?","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/288222"},{"name":"webeasymail-pop3-bruteforce(9925)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9925.php"},{"name":"5519","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/5519"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-08-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2003-03-21T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020820 Advisory: DoS in WebEasyMail +more possible?","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/288222"},{"name":"webeasymail-pop3-bruteforce(9925)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9925.php"},{"name":"5519","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/5519"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1416","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020820 Advisory: DoS in WebEasyMail +more possible?","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/288222"},{"name":"webeasymail-pop3-bruteforce(9925)","refsource":"XF","url":"http://www.iss.net/security_center/static/9925.php"},{"name":"5519","refsource":"BID","url":"http://www.securityfocus.com/bid/5519"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1416","datePublished":"2003-03-18T05:00:00.000Z","dateReserved":"2003-02-05T00:00:00.000Z","dateUpdated":"2024-08-08T03:26:27.339Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-04-11 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:webeasymail:webeasymail:*:*:*:*:*:*:*:*","versionEndIncluding":"3.4.2.2","matchCriteriaId":"CFE7C3F6-F18A-45F3-8289-10CE2DAF3E56"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1416","Ordinal":"1","Title":"CVE-2002-1416","CVE":"CVE-2002-1416","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1416","Ordinal":"1","NoteData":"The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.","Type":"Description","Title":"CVE-2002-1416"},{"CveYear":"2002","CveId":"1416","Ordinal":"2","NoteData":"2003-03-18","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1416","Ordinal":"3","NoteData":"2003-03-21","Type":"Other","Title":"Modified"}]}}}