Vulnerabilities > Netscape > Navigator > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-08-06 CVE-2004-0528 Unspecified vulnerability in Netscape Navigator 7.1
Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
network
low complexity
netscape
5.0
2003-12-31 CVE-2003-1560 Information Exposure vulnerability in Netscape Navigator 4
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
network
low complexity
netscape CWE-200
5.0
2003-12-31 CVE-2003-1492 Link Following vulnerability in multiple products
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra .
network
low complexity
mozilla netscape CWE-59
5.0
2003-12-31 CVE-2003-1419 Improper Input Validation vulnerability in Netscape Navigator 7.0
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
network
netscape CWE-20
4.3
2002-12-31 CVE-2002-2338 Improper Input Validation vulnerability in multiple products
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
network
low complexity
mozilla netscape CWE-20
5.0
2002-12-31 CVE-2002-2013 Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
network
low complexity
mozilla netscape
5.0
2002-06-25 CVE-2002-0354 The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
network
low complexity
mozilla netscape
5.0
2002-06-18 CVE-2002-0594 Local File Detection vulnerability in Netscape/Mozilla/Galeon
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
network
low complexity
galeon mozilla netscape
5.0
2000-01-12 CVE-2000-0087 Unspecified vulnerability in Netscape Communicator and Navigator
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
network
low complexity
netscape
5.0