Vulnerabilities > Netscape > Navigator > 7.0

DATE CVE VULNERABILITY TITLE RISK
2006-06-07 CVE-2006-2894 Improper Input Validation vulnerability in multiple products
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.
network
high complexity
mozilla netscape CWE-20
4.0
2005-12-09 CVE-2005-4134 Buffer Overflow vulnerability in Mozilla Firefox Large History File
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup.
network
low complexity
k-meleon-project mozilla netscape
5.0
2005-01-10 CVE-2004-1160 Remote Window Hijacking vulnerability in Netscape
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
netscape
7.5
2004-12-31 CVE-2004-0904 Integer Overflow vulnerability in Mozilla Browser BMP Image Decoding
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
network
low complexity
mozilla netscape conectiva redhat
critical
10.0
2004-09-14 CVE-2004-0905 Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
local
low complexity
mozilla netscape conectiva redhat suse
4.6
2004-08-18 CVE-2004-0722 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
network
low complexity
mozilla netscape
critical
10.0
2003-12-31 CVE-2003-1419 Improper Input Validation vulnerability in Netscape Navigator 7.0
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
network
netscape CWE-20
4.3
2003-12-31 CVE-2003-1265 Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
local
low complexity
mozilla netscape
2.1
2002-11-29 CVE-2002-1308 Remote Heap Corruption vulnerability in Netscape/Mozilla JAR
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
network
low complexity
mozilla netscape
7.5