📦

communicator

Vendor: netscape

Actively Exploited 0 CISA KEV List
PoC / Exploits 9 Code Available
Total RCEs 4 Remote Access
Total CVEs 56 Total Indexed
Avg. EPSS 3.42% Exploit Prob.
Latest CVE CVE-2002-1766 Dec 31

Security Vulnerability Index

Page 2 / 6
7.5 CVSS

Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.

EPSS: 1.43%
7.5 CVSS
CVE-2000-0711
Exploit Found

Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.

EPSS: 7.45%
5.0 CVSS
CVE-2000-0676
Exploit Found

Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.

EPSS: 29.14%
5.0 CVSS
CVE-2000-0655
Exploit Found

Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.

EPSS: 15.25%
5.0 CVSS

Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.

EPSS: 0.95%
3.7 CVSS
CVE-2000-0409
Exploit Found

Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.

EPSS: 0.20%
2.6 CVSS

Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.

EPSS: 0.74%
2.6 CVSS

A remote attacker can read information from a Netscape user's cache via JavaScript.

EPSS: 0.35%
5.0 CVSS

Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.

EPSS: 0.81%
5.0 CVSS

Netscape Navigator uses weak encryption for storing a user's Netscape mail password.

EPSS: 0.30%