Netscape Navigator vulnerabilities
38 known vulnerabilities affecting netscape/navigator.
Total CVEs
38
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH14MEDIUM17LOW4
Vulnerabilities
Page 2 of 2
CVE-2003-1419MEDIUMCVSS 4.3PoCv7.02003-12-31
CVE-2003-1419 [MEDIUM] CWE-20 CVE-2003-1419: Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an inv
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
nvd
CVE-2003-1492MEDIUMCVSS 5.0v7.0.22003-12-31
CVE-2003-1492 [MEDIUM] CWE-59 CVE-2003-1492: Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a diffe
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.
nvd
CVE-2003-1560MEDIUMCVSS 5.0v42003-12-31
CVE-2003-1560 [MEDIUM] CWE-200 CVE-2003-1560: Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
nvd
CVE-2003-1265LOWCVSS 2.1v7.02003-12-31
CVE-2003-1265 [LOW] CVE-2003-1265: Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users selec
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
nvd
CVE-2003-0553HIGHCVSS 7.5v7.0.22003-08-18
CVE-2003-0553 [HIGH] CVE-2003-0553: Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remot
Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.
nvd
CVE-2002-2061HIGHCVSS 7.5v6.2.32002-12-31
CVE-2002-2061 [HIGH] CVE-2002-2061: Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.
nvd
CVE-2002-2338MEDIUMCVSS 5.0PoCv6.0v6.01+4 more2002-12-31
CVE-2002-2338 [MEDIUM] CWE-20 CVE-2002-2338: The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows r
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
nvd
CVE-2002-2013MEDIUMCVSS 5.0v4.77v6.0+3 more2002-12-31
CVE-2002-2013 [MEDIUM] CVE-2002-2013: Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
nvd
CVE-2002-1308HIGHCVSS 7.5v6.2v6.2.1+3 more2002-11-29
CVE-2002-1308 [HIGH] CVE-2002-1308: Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
nvd
CVE-2002-1091HIGHCVSS 7.5v6.2v6.2.1+2 more2002-10-04
CVE-2002-1091 [HIGH] CVE-2002-1091: Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and exe
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
nvd
CVE-2002-0354MEDIUMCVSS 5.0v6.1v6.22002-06-25
CVE-2002-0354 [MEDIUM] CVE-2002-0354: The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to rea
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
nvd
CVE-2002-0593HIGHCVSS 7.5v6.0v6.012002-06-18
CVE-2002-0593 [HIGH] CVE-2002-0593: Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a den
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
nvd
CVE-2002-0594MEDIUMCVSS 5.0v6.0v6.01+4 more2002-06-18
CVE-2002-0594 [MEDIUM] CVE-2002-0594: Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of fil
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
nvd
CVE-2000-1187HIGHCVSS 7.5≤ 4.752001-01-09
CVE-2000-1187 [HIGH] CVE-2000-1187: Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.
nvd
CVE-1999-1189HIGHCVSS 7.5v4.71999-11-24
CVE-1999-1189 [HIGH] CVE-1999-1189: Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote a
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
nvd
CVE-1999-0827LOWCVSS 2.6≤ 4.51999-11-01
CVE-1999-0827 [LOW] CVE-1999-0827: By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across differe
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
nvd
CVE-1999-0440HIGHCVSS 7.5v4.0v4.01+9 more1999-03-01
CVE-1999-0440 [HIGH] CVE-1999-0440: The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through m
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
nvd
CVE-1999-0141LOWCVSS 3.7v2.021996-03-29
CVE-1999-0141 [LOW] CVE-1999-0141: Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the app
Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.
nvd
← Previous2 / 2