VYPR

Netscape

by Netscape

CVEs (43)

  • CVE-2005-2260Jul 13, 2005
    risk 0.00cvss epss 0.03

    The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally…

  • CVE-2004-1160Jan 10, 2005
    risk 0.00cvss epss 0.02

    Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site,…

  • CVE-2004-0718Jul 27, 2004
    risk 0.00cvss epss 0.02

    The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame…

  • CVE-2003-1265Dec 31, 2003
    risk 0.00cvss epss 0.00

    Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.

  • CVE-2003-1560Dec 31, 2003
    risk 0.00cvss epss 0.01

    Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

  • CVE-2002-2061Dec 31, 2002
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.

  • CVE-2002-2013Dec 31, 2002
    risk 0.00cvss epss 0.02

    Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.

  • CVE-2002-2248Dec 31, 2002
    risk 0.00cvss epss 0.06

    Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.

  • CVE-2002-1091Oct 4, 2002
    risk 0.00cvss epss 0.04

    Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.

  • CVE-2002-0815Aug 12, 2002
    risk 0.00cvss epss 0.04

    The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted…

  • CVE-2002-0354Jun 25, 2002
    risk 0.00cvss epss 0.01

    The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText…

  • CVE-2002-0594Jun 18, 2002
    risk 0.00cvss epss 0.02

    Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.

  • CVE-2002-0593Jun 18, 2002
    risk 0.00cvss epss 0.04

    Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.

  • CVE-2001-0921Nov 21, 2001
    risk 0.00cvss epss 0.01

    Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext.

  • CVE-2001-0745Oct 18, 2001
    risk 0.00cvss epss 0.02

    Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property.

  • CVE-2001-1066Aug 31, 2001
    risk 0.00cvss epss 0.00

    ns6install installation script for Netscape 6.01 on Solaris, and other versions including 6.2.1 beta, allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2000-1187Jan 9, 2001
    risk 0.00cvss epss 0.03

    Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.

  • CVE-2000-0517May 26, 2000
    risk 0.00cvss epss 0.01

    Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS…

  • CVE-1999-0790Apr 1, 2000
    risk 0.00cvss epss 0.01

    A remote attacker can read information from a Netscape user's cache via JavaScript.

  • CVE-2000-0034Dec 22, 1999
    risk 0.00cvss epss 0.01

    Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."