Vulnerabilities
Vulnerable Software
Netscape:  Security Vulnerabilities
Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.
CVSS Score
10.0
EPSS Score
0.003
Published
2001-03-12
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.
CVSS Score
7.5
EPSS Score
0.014
Published
2001-01-09
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
CVSS Score
5.0
EPSS Score
0.009
Published
2000-12-19
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
CVSS Score
10.0
EPSS Score
0.008
Published
2000-12-19
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.
CVSS Score
10.0
EPSS Score
0.011
Published
2000-12-11
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.
CVSS Score
7.2
EPSS Score
0.002
Published
2000-12-11
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.
CVSS Score
7.2
EPSS Score
0.001
Published
2000-12-11
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.
CVSS Score
10.0
EPSS Score
0.065
Published
2000-12-11
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.
CVSS Score
5.0
EPSS Score
0.04
Published
2000-12-11
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.
CVSS Score
10.0
EPSS Score
0.005
Published
2000-12-11


Contact Us

Shodan ® - All rights reserved