Vulnerabilities (CVE)

Filtered by vendor Netscape Subscribe
Total 120 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0921 1 Netscape 1 Communicator 2023-12-10 2.1 LOW N/A
Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext.
CVE-2000-0960 1 Netscape 1 Messaging Server 2023-12-10 5.0 MEDIUM N/A
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
CVE-2001-0262 1 Netscape 1 Smartdownload 2023-12-10 7.5 HIGH N/A
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
CVE-2002-2284 1 Netscape 1 Communicator 2023-12-10 6.4 MEDIUM N/A
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.
CVE-2002-1204 1 Netscape 1 Communicator 2023-12-10 5.0 MEDIUM N/A
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
CVE-2001-0683 1 Netscape 1 Collabra Server 2023-12-10 5.0 MEDIUM N/A
Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.
CVE-2000-1073 1 Netscape 1 Iplanet Ical 2023-12-10 7.2 HIGH N/A
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.
CVE-1999-0686 2 Hp, Netscape 2 Hp-ux, Enterprise Server 2023-12-10 5.0 MEDIUM N/A
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
CVE-2000-0711 2 Microsoft, Netscape 2 Virtual Machine, Communicator 2023-12-10 7.5 HIGH N/A
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
CVE-1999-0762 1 Netscape 2 Communicator, Navigator 2023-12-10 2.6 LOW N/A
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.
CVE-2000-0676 1 Netscape 1 Communicator 2023-12-10 5.0 MEDIUM N/A
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.
CVE-2002-2248 1 Netscape 1 Communicator 2023-12-10 10.0 HIGH N/A
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.
CVE-1999-0424 1 Netscape 1 Communicator 2023-12-10 2.1 LOW N/A
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
CVE-2002-1654 2 Iplanet, Netscape 2 Iplanet Web Server, Enterprise Server 2023-12-10 7.5 HIGH N/A
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
CVE-2002-1308 2 Mozilla, Netscape 2 Mozilla, Navigator 2023-12-10 7.5 HIGH N/A
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
CVE-1999-0827 2 Microsoft, Netscape 3 Ie, Internet Explorer, Navigator 2023-12-10 2.6 LOW N/A
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
CVE-2003-1265 2 Mozilla, Netscape 2 Mozilla, Navigator 2023-12-10 2.1 LOW N/A
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
CVE-1999-0807 1 Netscape 1 Directory Server 2023-12-10 7.2 HIGH N/A
The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.
CVE-2001-0684 1 Netscape 1 Collabra Server 2023-12-10 5.0 MEDIUM N/A
Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.
CVE-2002-0815 3 Microsoft, Mozilla, Netscape 3 Internet Explorer, Mozilla, Navigator 2023-12-10 7.5 HIGH N/A
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain.