Vulnerabilities
Vulnerable Software
Netscape:  >> Communicator  Security Vulnerabilities
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.
CVSS Score
7.5
EPSS Score
0.014
Published
2001-01-09
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.
CVSS Score
5.0
EPSS Score
0.252
Published
2000-10-20
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
CVSS Score
7.5
EPSS Score
0.068
Published
2000-10-20
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.
CVSS Score
5.0
EPSS Score
0.152
Published
2000-07-25
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.
CVSS Score
5.0
EPSS Score
0.01
Published
2000-05-26
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
CVSS Score
2.6
EPSS Score
0.007
Published
2000-05-10
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.
CVSS Score
3.7
EPSS Score
0.001
Published
2000-05-10
A remote attacker can read information from a Netscape user's cache via JavaScript.
CVSS Score
2.6
EPSS Score
0.004
Published
2000-04-01
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
CVSS Score
5.0
EPSS Score
0.003
Published
2000-01-12
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
CVSS Score
5.0
EPSS Score
0.008
Published
2000-01-12


Contact Us

Shodan ® - All rights reserved