netscape records
120 published records for vendor netscape.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.8%
- Pre-auth RCE
- 26
- With a fix record
- 9.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAll records
120 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-1999-0043No exploit | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Critical9.8 | — | 44.6% | Dec 4, 1996 |
46Plan | CVE-1999-0005Proof of concept | Arbitrary command execution via IMAP buffer overflow in authenticate command.netscape · messaging server | Critical10.0 | — | 18.4% | Jul 20, 1998 |
44Plan | CVE-2004-0722Proof of concept | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versimozilla · mozilla | Critical10.0 | — | 13.2% | Aug 18, 2004 |
43Plan | CVE-2004-1236No exploit | Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers tnetscape · directory server | Critical10.0 | — | 8.9% | Dec 31, 2004 |
42Plan | CVE-2004-0904No exploit | Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.mozilla · firefox | Critical10.0 | — | 8.0% | Dec 31, 2004 |
42Plan | CVE-2002-2248No exploit | Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbinetscape · communicator · CWE-119 | Critical10.0 | — | 5.8% | Dec 31, 2002 |
41Plan | CVE-2007-3924No exploit | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registeredmicrosoft · internet explorer | Critical9.3 | — | 13.6% | Jul 20, 2007 |
41Plan | CVE-2000-0577Proof of concept | Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a ..netscape · professional services ftpserver | Critical10.0 | — | 4.5% | Jun 21, 2000 |
41Plan | CVE-2000-1074Proof of concept | csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser accnetscape · iplanet ical | Critical10.0 | — | 4.1% | Dec 11, 2000 |
41Plan | CVE-1999-0853No exploit | Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Aunetscape · enterprise server | Critical10.0 | — | 3.4% | Dec 1, 1999 |
41Plan | CVE-2000-1071No exploit | The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackersnetscape · iplanet ical | Critical10.0 | — | 3.0% | Dec 11, 2000 |
41Plan | CVE-2000-0961No exploit | Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST conetscape · messaging server | Critical10.0 | — | 2.4% | Dec 19, 2000 |
41Plan | CVE-2000-0308No exploit | Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allnetscape · enterprise server | Critical10.0 | — | 2.2% | Mar 12, 2001 |
40Plan | CVE-2000-0711Proof of concept | Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackernetscape · communicator | High7.5 | — | 33.5% | Oct 20, 2000 |
40Plan | CVE-2000-1076No exploit | Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could netscape · directory server | Critical10.0 | — | 1.6% | Dec 11, 2000 |
38Monitor | CVE-1999-0045Proof of concept | List of arbitrary files on Web host via nph-test-cgi script.apache · http server | High7.5 | — | 26.0% | Dec 10, 1996 |
37Monitor | CVE-2004-0826No exploit | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modifnetscape · certificate server | High7.5 | — | 22.5% | Dec 31, 2004 |
35Monitor | CVE-2006-4253Proof of concept | Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly emozilla · firefox · CWE-264 | High7.6 | — | 15.2% | Aug 21, 2006 |
34Monitor | CVE-1999-0012No exploit | Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.microsoft · frontpage · CWE-290 | High7.0 | — | 18.5% | Feb 6, 1998 |
33Monitor | CVE-2007-4042No exploit | Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%0netscape · navigator | High7.5 | — | 10.3% | Jul 27, 2007 |
33Monitor | CVE-2001-0596Proof of concept | Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascrnetscape · communicator | High7.5 | — | 8.7% | Aug 2, 2001 |
32Monitor | CVE-1999-0239Proof of concept | Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.netscape · fasttrack server · CWE-178 | High7.5 | — | 7.6% | Jan 1, 1998 |
32Monitor | CVE-2001-0262Proof of concept | Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.netscape · smartdownload | High7.5 | — | 7.5% | Jul 2, 2001 |
32Monitor | CVE-1999-0537No exploit | A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Jnetscape · communicator | High7.5 | — | 6.0% | Apr 1, 1998 |
31Monitor | CVE-2002-1091No exploit | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image withmozilla · mozilla | High7.5 | — | 4.3% | Oct 4, 2002 |
- CVE-1999-004352Plan
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
CriticalCVSS 9.8No exploitEPSS 45%isc · innDec 4, 1996
- CVE-1999-000546Plan
Arbitrary command execution via IMAP buffer overflow in authenticate command.
CriticalCVSS 10.0Proof of conceptEPSS 18%netscape · messaging serverJul 20, 1998
- CVE-2004-072244Plan
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versi
CriticalCVSS 10.0Proof of conceptEPSS 13%mozilla · mozillaAug 18, 2004
- CVE-2004-123643Plan
Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers t
CriticalCVSS 10.0No exploitEPSS 9%netscape · directory serverDec 31, 2004
- CVE-2004-090442Plan
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.
CriticalCVSS 10.0No exploitEPSS 8%mozilla · firefoxDec 31, 2004
- CVE-2002-224842Plan
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbi
CriticalCVSS 10.0No exploitEPSS 6%netscape · communicatorDec 31, 2002
- CVE-2007-392441Plan
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered
CriticalCVSS 9.3No exploitEPSS 14%microsoft · internet explorerJul 20, 2007
- CVE-2000-057741Plan
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a ..
CriticalCVSS 10.0Proof of conceptEPSS 5%netscape · professional services ftpserverJun 21, 2000
- CVE-2000-107441Plan
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser acc
CriticalCVSS 10.0Proof of conceptEPSS 4%netscape · iplanet icalDec 11, 2000
- CVE-1999-085341Plan
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Au
CriticalCVSS 10.0No exploitEPSS 3%netscape · enterprise serverDec 1, 1999
- CVE-2000-107141Plan
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers
CriticalCVSS 10.0No exploitEPSS 3%netscape · iplanet icalDec 11, 2000
- CVE-2000-096141Plan
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST co
CriticalCVSS 10.0No exploitEPSS 2%netscape · messaging serverDec 19, 2000
- CVE-2000-030841Plan
Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 all
CriticalCVSS 10.0No exploitEPSS 2%netscape · enterprise serverMar 12, 2001
- CVE-2000-071140Plan
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attacker
HighCVSS 7.5Proof of conceptEPSS 34%netscape · communicatorOct 20, 2000
- CVE-2000-107640Plan
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could
CriticalCVSS 10.0No exploitEPSS 2%netscape · directory serverDec 11, 2000
- CVE-1999-004538Monitor
List of arbitrary files on Web host via nph-test-cgi script.
HighCVSS 7.5Proof of conceptEPSS 26%apache · http serverDec 10, 1996
- CVE-2004-082637Monitor
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modif
HighCVSS 7.5No exploitEPSS 23%netscape · certificate serverDec 31, 2004
- CVE-2006-425335Monitor
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly e
HighCVSS 7.6Proof of conceptEPSS 15%mozilla · firefoxAug 21, 2006
- CVE-1999-001234Monitor
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
HighCVSS 7.0No exploitEPSS 19%microsoft · frontpageFeb 6, 1998
- CVE-2007-404233Monitor
Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%0
HighCVSS 7.5No exploitEPSS 10%netscape · navigatorJul 27, 2007
- CVE-2001-059633Monitor
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascr
HighCVSS 7.5Proof of conceptEPSS 9%netscape · communicatorAug 2, 2001
- CVE-1999-023932Monitor
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
HighCVSS 7.5Proof of conceptEPSS 8%netscape · fasttrack serverJan 1, 1998
- CVE-2001-026232Monitor
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
HighCVSS 7.5Proof of conceptEPSS 7%netscape · smartdownloadJul 2, 2001
- CVE-1999-053732Monitor
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, J
HighCVSS 7.5No exploitEPSS 6%netscape · communicatorApr 1, 1998
- CVE-2002-109131Monitor
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with
HighCVSS 7.5No exploitEPSS 4%mozilla · mozillaOct 4, 2002