Skip to content
Noroxi

netscape records

120 published records for vendor netscape.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 0.8%
Pre-auth RCE
26
With a fix record
9.2%
Median publish → KEV
No record has entered KEV

All records

120 records
  • Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.

    CriticalCVSS 9.8No exploitEPSS 45%

    isc · innDec 4, 1996

  • Arbitrary command execution via IMAP buffer overflow in authenticate command.

    CriticalCVSS 10.0Proof of conceptEPSS 18%

    netscape · messaging serverJul 20, 1998

  • Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versi

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    mozilla · mozillaAug 18, 2004

  • Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers t

    CriticalCVSS 10.0No exploitEPSS 9%

    netscape · directory serverDec 31, 2004

  • Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.

    CriticalCVSS 10.0No exploitEPSS 8%

    mozilla · firefoxDec 31, 2004

  • Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbi

    CriticalCVSS 10.0No exploitEPSS 6%

    netscape · communicatorDec 31, 2002

  • Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered

    CriticalCVSS 9.3No exploitEPSS 14%

    microsoft · internet explorerJul 20, 2007

  • Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a ..

    CriticalCVSS 10.0Proof of conceptEPSS 5%

    netscape · professional services ftpserverJun 21, 2000

  • csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser acc

    CriticalCVSS 10.0Proof of conceptEPSS 4%

    netscape · iplanet icalDec 11, 2000

  • Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Au

    CriticalCVSS 10.0No exploitEPSS 3%

    netscape · enterprise serverDec 1, 1999

  • The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers

    CriticalCVSS 10.0No exploitEPSS 3%

    netscape · iplanet icalDec 11, 2000

  • Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST co

    CriticalCVSS 10.0No exploitEPSS 2%

    netscape · messaging serverDec 19, 2000

  • Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 all

    CriticalCVSS 10.0No exploitEPSS 2%

    netscape · enterprise serverMar 12, 2001

  • Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attacker

    HighCVSS 7.5Proof of conceptEPSS 34%

    netscape · communicatorOct 20, 2000

  • Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could

    CriticalCVSS 10.0No exploitEPSS 2%

    netscape · directory serverDec 11, 2000

  • CVE-1999-0045
    38Monitor

    List of arbitrary files on Web host via nph-test-cgi script.

    HighCVSS 7.5Proof of conceptEPSS 26%

    apache · http serverDec 10, 1996

  • CVE-2004-0826
    37Monitor

    Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modif

    HighCVSS 7.5No exploitEPSS 23%

    netscape · certificate serverDec 31, 2004

  • CVE-2006-4253
    35Monitor

    Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly e

    HighCVSS 7.6Proof of conceptEPSS 15%

    mozilla · firefoxAug 21, 2006

  • CVE-1999-0012
    34Monitor

    Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.

    HighCVSS 7.0No exploitEPSS 19%

    microsoft · frontpageFeb 6, 1998

  • CVE-2007-4042
    33Monitor

    Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%0

    HighCVSS 7.5No exploitEPSS 10%

    netscape · navigatorJul 27, 2007

  • CVE-2001-0596
    33Monitor

    Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascr

    HighCVSS 7.5Proof of conceptEPSS 9%

    netscape · communicatorAug 2, 2001

  • CVE-1999-0239
    32Monitor

    Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.

    HighCVSS 7.5Proof of conceptEPSS 8%

    netscape · fasttrack serverJan 1, 1998

  • CVE-2001-0262
    32Monitor

    Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.

    HighCVSS 7.5Proof of conceptEPSS 7%

    netscape · smartdownloadJul 2, 2001

  • CVE-1999-0537
    32Monitor

    A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, J

    HighCVSS 7.5No exploitEPSS 6%

    netscape · communicatorApr 1, 1998

  • CVE-2002-1091
    31Monitor

    Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with

    HighCVSS 7.5No exploitEPSS 4%

    mozilla · mozillaOct 4, 2002