Vulnerabilities
Vulnerable Software
Netscape:  >> Communicator  Security Vulnerabilities
Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
CVSS Score
4.6
EPSS Score
0.002
Published
1999-12-24
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."
CVSS Score
5.0
EPSS Score
0.006
Published
1999-12-22
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
CVSS Score
7.5
EPSS Score
0.024
Published
1999-11-24
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.
CVSS Score
2.6
EPSS Score
0.005
Published
1999-10-28
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.
CVSS Score
7.5
EPSS Score
0.012
Published
1999-10-05
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
CVSS Score
5.1
EPSS Score
0.03
Published
1999-09-02
Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed".
CVSS Score
5.0
EPSS Score
0.006
Published
1999-07-09
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.
CVSS Score
2.6
EPSS Score
0.003
Published
1999-05-24
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
CVSS Score
2.1
EPSS Score
0.001
Published
1999-03-18
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
CVSS Score
6.4
EPSS Score
0.004
Published
1999-03-18


Contact Us

Shodan ® - All rights reserved