CVE-2000-1187
- EPSS 1.43%
- Published 09.01.2001 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.
CVE-2000-0711
- EPSS 6.75%
- Published 20.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
- EPSS 25.17%
- Published 20.10.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.
- EPSS 15.25%
- Published 25.07.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.
- EPSS 0.95%
- Published 26.05.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromi...
CVE-2000-0409
- EPSS 0.09%
- Published 10.05.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.
CVE-2000-0406
- EPSS 0.74%
- Published 10.05.2000 04:00:00
- Last modified 03.04.2025 01:03:51
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acr...
CVE-1999-0790
- EPSS 0.35%
- Published 01.04.2000 05:00:00
- Last modified 03.04.2025 01:03:51
A remote attacker can read information from a Netscape user's cache via JavaScript.
- EPSS 0.81%
- Published 12.01.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
- EPSS 0.31%
- Published 12.01.2000 05:00:00
- Last modified 03.04.2025 01:03:51
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.