.xbiff2rc is world-readable, making it's possible to retrieve POP3 / IMAP account password.
vulners.com/securityvulns/securityvulns:doc:14089