Skip to main content

Vendor/product archive

netscape / communicator CVEs

Beta · best-effort

31 CVEs tagged to netscape / communicator1 Critical, 7 High, 16 Medium, 7 Low, 0 Unrated.

CVE-2002-1766

Published Dec 31, 2002

Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2248

Published Dec 31, 2002

Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-2284

Published Dec 31, 2002

Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2308

Published Dec 31, 2002

Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1204

Published Nov 29, 2002

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possib…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0921

Published Nov 21, 2001

Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been ty…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0596

Published Aug 2, 2001

Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1187

Published Jan 9, 2001

Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0676

Published Oct 20, 2000

Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http"…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0711

Published Oct 20, 2000

Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's sy…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0655

Published Jul 25, 2000

Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal fie…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0517

Published May 26, 2000

Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0406

Published May 10, 2000

Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic f…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0409

Published May 10, 2000

Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-0790

Published Apr 1, 2000

A remote attacker can read information from a Netscape user's cache via JavaScript.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-1002

Published Jan 12, 2000

Netscape Navigator uses weak encryption for storing a user's Netscape mail password.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0087

Published Jan 12, 2000

Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0892

Published Dec 24, 1999

Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0034

Published Dec 22, 1999

Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1189

Published Nov 24, 1999

Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1226

Published Oct 28, 1999

Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-1357

Published Oct 5, 1999

Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2