Netscape Communicator vulnerabilities
34 known vulnerabilities affecting netscape/communicator.
Total CVEs
34
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM18LOW8
Vulnerabilities
Page 2 of 2
CVE-1999-0892MEDIUMCVSS 4.6v4.51999-12-24
CVE-1999-0892 [MEDIUM] CVE-1999-0892: Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less th
Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
nvd
CVE-2000-0034MEDIUMCVSS 5.0v4.71999-12-22
CVE-2000-0034 [MEDIUM] CVE-2000-0034: Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even i
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."
nvd
CVE-1999-1189HIGHCVSS 7.5v4.71999-11-24
CVE-1999-1189 [HIGH] CVE-1999-1189: Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote a
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
nvd
CVE-1999-1226LOWCVSS 2.6≤ 4.71999-10-28
CVE-1999-1226 [LOW] CVE-1999-1226: Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and poss
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.
nvd
CVE-1999-1357HIGHCVSS 7.5≤ 4.7v4.04+1 more1999-10-05
CVE-1999-1357 [HIGH] CVE-1999-1357: Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating syste
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.
nvd
CVE-1999-0685MEDIUMCVSS 5.1PoCv4.5v4.06+3 more1999-09-02
CVE-1999-0685 [MEDIUM] CVE-1999-0685: Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
nvd
CVE-1999-0809MEDIUMCVSS 5.0v4.01999-07-09
CVE-1999-0809 [MEDIUM] CVE-1999-0809: Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if t
Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed".
nvd
CVE-1999-0762LOWCVSS 2.6v4.6v4.x1999-05-24
CVE-1999-0762 [LOW] CVE-1999-0762: When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.
nvd
CVE-1999-0425MEDIUMCVSS 6.4v4.51999-03-18
CVE-1999-0425 [MEDIUM] CVE-1999-0425: talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Nets
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
nvd
CVE-1999-0424LOWCVSS 2.1v4.51999-03-18
CVE-1999-0424 [LOW] CVE-1999-0424: talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Nets
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
nvd
CVE-1999-0440HIGHCVSS 7.5v4.51999-03-01
CVE-1999-0440 [HIGH] CVE-1999-0440: The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through m
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
nvd
CVE-1999-1262MEDIUMCVSS 5.1v4.01v4.5+3 more1997-08-01
CVE-1999-1262 [MEDIUM] CVE-1999-1262: Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the o
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.
nvd
CVE-1999-0031LOWCVSS 2.6v2.0v3.0+1 more1997-07-08
CVE-1999-0031 [LOW] CVE-1999-0031: JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
nvd
CVE-1999-0174MEDIUMCVSS 6.4PoCv4.0v4.05+5 more1997-02-01
CVE-1999-0174 [MEDIUM] CVE-1999-0174: The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attac
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
nvd
← Previous2 / 2