5

CVE-2002-1204

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetscapeCommunicator Version4.6
NetscapeCommunicator Version4.7
NetscapeCommunicator Version4.61
NetscapeCommunicator Version4.72
NetscapeCommunicator Version4.73
NetscapeCommunicator Version4.74
NetscapeCommunicator Version4.75
NetscapeCommunicator Version4.76
NetscapeCommunicator Version4.77
NetscapeCommunicator Version4.78
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.85% 0.74
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N