Vulnerabilities (CVE)

Filtered by vendor Netscape Subscribe
Filtered by product Communicator
Total 35 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-0892 1 Netscape 1 Communicator 2024-02-28 4.6 MEDIUM N/A
Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
CVE-2002-2338 2 Mozilla, Netscape 3 Mozilla, Communicator, Navigator 2024-02-28 5.0 MEDIUM N/A
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
CVE-2000-0655 2 Mozilla, Netscape 2 Mozilla, Communicator 2024-02-28 5.0 MEDIUM N/A
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.
CVE-2000-0517 1 Netscape 1 Communicator 2024-02-28 5.0 MEDIUM N/A
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.
CVE-2001-0921 1 Netscape 1 Communicator 2024-02-28 2.1 LOW N/A
Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext.
CVE-1999-0440 2 Netscape, Sun 3 Communicator, Navigator, Java 2024-02-28 7.5 HIGH N/A
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
CVE-2000-0409 1 Netscape 1 Communicator 2024-02-28 3.7 LOW N/A
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.
CVE-1999-0425 1 Netscape 1 Communicator 2024-02-28 6.4 MEDIUM N/A
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
CVE-2000-1187 1 Netscape 2 Communicator, Navigator 2024-02-28 7.5 HIGH N/A
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.
CVE-2002-0593 2 Mozilla, Netscape 3 Mozilla, Communicator, Navigator 2024-02-28 7.5 HIGH N/A
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
CVE-1999-0685 1 Netscape 1 Communicator 2024-02-28 5.1 MEDIUM N/A
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
CVE-2002-2013 2 Mozilla, Netscape 3 Mozilla, Communicator, Navigator 2024-02-28 5.0 MEDIUM N/A
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
CVE-2002-2248 1 Netscape 1 Communicator 2024-02-28 10.0 HIGH N/A
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.
CVE-1999-0790 1 Netscape 1 Communicator 2024-02-28 2.6 LOW N/A
A remote attacker can read information from a Netscape user's cache via JavaScript.
CVE-2000-0711 2 Microsoft, Netscape 2 Virtual Machine, Communicator 2024-02-28 7.5 HIGH N/A
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.