Vulnerabilities > Netscape > Navigator
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-06-25 | CVE-2002-0354 | The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. | 5.0 |
2002-06-18 | CVE-2002-0594 | Local File Detection vulnerability in Netscape/Mozilla/Galeon Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. | 5.0 |
2002-06-18 | CVE-2002-0593 | Buffer Overflow vulnerability in Netscape/Mozilla IRC Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. | 7.5 |
2001-01-09 | CVE-2000-1187 | Unspecified vulnerability in Netscape Communicator and Navigator Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. | 7.5 |
2000-01-12 | CVE-2000-0087 | Unspecified vulnerability in Netscape Communicator and Navigator Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. | 5.0 |
1999-11-24 | CVE-1999-1189 | Unspecified vulnerability in Netscape Communicator and Navigator Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file. | 7.5 |
1999-11-01 | CVE-1999-0827 | By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | 2.6 |
1999-05-24 | CVE-1999-0762 | Unspecified vulnerability in Netscape Communicator and Navigator When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. | 2.6 |
1999-03-01 | CVE-1999-0440 | The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages. | 7.5 |
1998-12-01 | CVE-1999-0869 | Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. | 2.6 |