Vulnerabilities (CVE)

Filtered by vendor Netscape Subscribe
Total 120 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0406 1 Netscape 1 Communicator 2025-04-03 2.6 LOW N/A
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
CVE-2000-1071 1 Netscape 1 Iplanet Ical 2025-04-03 10.0 HIGH N/A
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.
CVE-2001-0164 1 Netscape 1 Directory Server 2025-04-03 7.5 HIGH N/A
Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.
CVE-2002-0354 2 Mozilla, Netscape 2 Mozilla, Navigator 2025-04-03 5.0 MEDIUM N/A
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
CVE-2000-0087 1 Netscape 2 Communicator, Navigator 2025-04-03 5.0 MEDIUM N/A
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
CVE-1999-1262 1 Netscape 1 Communicator 2025-04-03 5.1 MEDIUM N/A
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.
CVE-2003-1265 2 Mozilla, Netscape 2 Mozilla, Navigator 2025-04-03 2.1 LOW N/A
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
CVE-2001-0683 1 Netscape 1 Collabra Server 2025-04-03 5.0 MEDIUM N/A
Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.
CVE-2004-0905 5 Conectiva, Mozilla, Netscape and 2 more 10 Linux, Firefox, Mozilla and 7 more 2025-04-03 4.6 MEDIUM N/A
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
CVE-2000-0034 1 Netscape 1 Communicator 2025-04-03 5.0 MEDIUM N/A
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."
CVE-2000-0236 1 Netscape 1 Enterprise Server 2025-04-03 5.0 MEDIUM N/A
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.
CVE-2006-1942 3 K-meleon Project, Mozilla, Netscape 3 K-meleon, Firefox, Navigator 2025-04-03 5.1 MEDIUM N/A
Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image for the broken image, as demonstrated using a .wma file to launch Windows Media Player, or by referencing an "alternate web page."
CVE-1999-0807 1 Netscape 1 Directory Server 2025-04-03 7.2 HIGH N/A
The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.
CVE-1999-0425 1 Netscape 1 Communicator 2025-04-03 6.4 MEDIUM N/A
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
CVE-2002-2308 1 Netscape 1 Communicator 2025-04-03 5.0 MEDIUM N/A
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.
CVE-1999-0005 2 Netscape, University Of Washington 2 Messaging Server, Imap 2025-04-03 10.0 HIGH N/A
Arbitrary command execution via IMAP buffer overflow in authenticate command.
CVE-2005-0989 2 Mozilla, Netscape 3 Firefox, Mozilla, Navigator 2025-04-03 5.0 MEDIUM N/A
The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
CVE-2002-1766 1 Netscape 1 Communicator 2025-04-03 4.6 MEDIUM N/A
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.
CVE-2003-1560 1 Netscape 1 Navigator 2025-04-03 5.0 MEDIUM N/A
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
CVE-2001-0175 1 Netscape 1 Fasttrack Server 2025-04-03 5.0 MEDIUM N/A
The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.