# CVE-2001-0990

## Summary

- **CVE ID:** CVE-2001-0990
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** N/A
- **Published:** Feb 2, 2002
- **Last Modified:** Mar 16, 2026

## Description

Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://www.inter7.com/vpopmail/ChangeLog)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/7076)
- [CNA](http://www.securityfocus.com/archive/1/212036)
- [CNA](http://www.securityfocus.com/bid/3284)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.07%
- **EPSS Percentile:** 21.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._