Home/Product/netscape communicator
Product

netscape communicator

35 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2002-2338
all versions
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a den
CVE-2002-2308
all versions
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a rec
CVE-2002-2284
all versions
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an apple
CVE-2002-2248
all versions
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to ex
CVE-2002-2013
all versions
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link wit
CVE-2002-1766
all versions
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font
CVE-2002-1204
all versions
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive informatio
CVE-2002-0593
all versions
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and pos
CVE-2001-0921
<= 4.77
Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing
CVE-2001-0596
<= 4.77
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains t
CVE-2000-1187
<= 4.75
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long
CVE-2000-0711
all versions
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remot
CVE-2000-0676
all versions
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to op
CVE-2000-0655
all versions
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JP
CVE-2000-0517
all versions
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted
CVE-2000-0409
all versions
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the u
CVE-2000-0406
all versions
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attack
CVE-1999-0790
all versions
A remote attacker can read information from a Netscape user's cache via JavaScript.
CVE-2000-0087
all versions
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preferenc
CVE-1999-1002
all versions
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
CVE-1999-0892
all versions
Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
CVE-2000-0034
all versions
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "re
CVE-1999-1189
all versions
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of
CVE-1999-1226
<= 4.7
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary command
CVE-1999-1357
<= 4.7
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character
CVE-1999-0685
all versions
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
CVE-1999-0809
all versions
Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option t
CVE-1999-0762
all versions
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to ga
CVE-1999-0425
all versions
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
CVE-1999-0424
all versions
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
CVE-1999-0440
all versions
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
CVE-1999-0537
all versions
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as Active
CVE-1999-1262
all versions
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was l
CVE-1999-0031
all versions
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activi
CVE-1999-0174
all versions
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin