5

CVE-2002-1204

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

Data is provided by the National Vulnerability Database (NVD)
NetscapeCommunicator Version4.6
NetscapeCommunicator Version4.7
NetscapeCommunicator Version4.61
NetscapeCommunicator Version4.72
NetscapeCommunicator Version4.73
NetscapeCommunicator Version4.74
NetscapeCommunicator Version4.75
NetscapeCommunicator Version4.76
NetscapeCommunicator Version4.77
NetscapeCommunicator Version4.78
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.85% 0.74
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N