📦

navigator

Vendor: netscape

Actively Exploited 2 CISA KEV List
PoC / Exploits 12 Code Available
Total RCEs 11 Remote Access
Total CVEs 53 Total Indexed
Avg. EPSS 9.79% Exploit Prob.
Latest CVE CVE-2023-29751 Jun 09

Security Vulnerability Index

Page 5 / 6
7.5 CVSS

Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.

EPSS: 1.43%
5.0 CVSS

Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.

EPSS: 0.81%
7.5 CVSS

Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.

EPSS: 2.35%
2.6 CVSS

By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.

EPSS: 0.88%
2.6 CVSS

When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.

EPSS: 0.30%
7.5 CVSS

The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.

EPSS: 1.62%