Записи netscape
120 опубликованных записей вендора netscape.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,8 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 9,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-255 Credentials Management Errors1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
120 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-1999-0043Эксплойта нет | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.isc · inn · CWE-78 | Критическая9,8 | — | 44,6 % | 4 дек. 1996 г. |
46В плане | CVE-1999-0005Proof of concept | Arbitrary command execution via IMAP buffer overflow in authenticate command.netscape · messaging server | Критическая10,0 | — | 18,4 % | 20 июл. 1998 г. |
44В плане | CVE-2004-0722Proof of concept | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versimozilla · mozilla | Критическая10,0 | — | 13,2 % | 18 авг. 2004 г. |
43В плане | CVE-2004-1236Эксплойта нет | Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers tnetscape · directory server | Критическая10,0 | — | 8,9 % | 31 дек. 2004 г. |
42В плане | CVE-2004-0904Эксплойта нет | Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.mozilla · firefox | Критическая10,0 | — | 8,0 % | 31 дек. 2004 г. |
42В плане | CVE-2002-2248Эксплойта нет | Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbinetscape · communicator · CWE-119 | Критическая10,0 | — | 5,8 % | 31 дек. 2002 г. |
41В плане | CVE-2007-3924Эксплойта нет | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registeredmicrosoft · internet explorer | Критическая9,3 | — | 13,6 % | 20 июл. 2007 г. |
41В плане | CVE-2000-0577Proof of concept | Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a ..netscape · professional services ftpserver | Критическая10,0 | — | 4,5 % | 21 июн. 2000 г. |
41В плане | CVE-2000-1074Proof of concept | csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser accnetscape · iplanet ical | Критическая10,0 | — | 4,1 % | 11 дек. 2000 г. |
41В плане | CVE-1999-0853Эксплойта нет | Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Aunetscape · enterprise server | Критическая10,0 | — | 3,4 % | 1 дек. 1999 г. |
41В плане | CVE-2000-1071Эксплойта нет | The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackersnetscape · iplanet ical | Критическая10,0 | — | 3,0 % | 11 дек. 2000 г. |
41В плане | CVE-2000-0961Эксплойта нет | Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST conetscape · messaging server | Критическая10,0 | — | 2,4 % | 19 дек. 2000 г. |
41В плане | CVE-2000-0308Эксплойта нет | Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allnetscape · enterprise server | Критическая10,0 | — | 2,2 % | 12 мар. 2001 г. |
40В плане | CVE-2000-0711Proof of concept | Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackernetscape · communicator | Высокая7,5 | — | 33,5 % | 20 окт. 2000 г. |
40В плане | CVE-2000-1076Эксплойта нет | Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could netscape · directory server | Критическая10,0 | — | 1,6 % | 11 дек. 2000 г. |
38Наблюдать | CVE-1999-0045Proof of concept | List of arbitrary files on Web host via nph-test-cgi script.apache · http server | Высокая7,5 | — | 26,0 % | 10 дек. 1996 г. |
37Наблюдать | CVE-2004-0826Эксплойта нет | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modifnetscape · certificate server | Высокая7,5 | — | 22,5 % | 31 дек. 2004 г. |
35Наблюдать | CVE-2006-4253Proof of concept | Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly emozilla · firefox · CWE-264 | Высокая7,6 | — | 15,2 % | 21 авг. 2006 г. |
34Наблюдать | CVE-1999-0012Эксплойта нет | Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.microsoft · frontpage · CWE-290 | Высокая7,0 | — | 18,5 % | 6 февр. 1998 г. |
33Наблюдать | CVE-2007-4042Эксплойта нет | Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%0netscape · navigator | Высокая7,5 | — | 10,3 % | 27 июл. 2007 г. |
33Наблюдать | CVE-2001-0596Proof of concept | Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascrnetscape · communicator | Высокая7,5 | — | 8,7 % | 2 авг. 2001 г. |
32Наблюдать | CVE-1999-0239Proof of concept | Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.netscape · fasttrack server · CWE-178 | Высокая7,5 | — | 7,6 % | 1 янв. 1998 г. |
32Наблюдать | CVE-2001-0262Proof of concept | Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.netscape · smartdownload | Высокая7,5 | — | 7,5 % | 2 июл. 2001 г. |
32Наблюдать | CVE-1999-0537Эксплойта нет | A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Jnetscape · communicator | Высокая7,5 | — | 6,0 % | 1 апр. 1998 г. |
31Наблюдать | CVE-2002-1091Эксплойта нет | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image withmozilla · mozilla | Высокая7,5 | — | 4,3 % | 4 окт. 2002 г. |
- CVE-1999-004352В плане
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
КритическаяCVSS 9,8Эксплойта нетEPSS 45 %isc · inn4 дек. 1996 г.
- CVE-1999-000546В плане
Arbitrary command execution via IMAP buffer overflow in authenticate command.
КритическаяCVSS 10,0Proof of conceptEPSS 18 %netscape · messaging server20 июл. 1998 г.
- CVE-2004-072244В плане
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versi
КритическаяCVSS 10,0Proof of conceptEPSS 13 %mozilla · mozilla18 авг. 2004 г.
- CVE-2004-123643В плане
Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers t
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %netscape · directory server31 дек. 2004 г.
- CVE-2004-090442В плане
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %mozilla · firefox31 дек. 2004 г.
- CVE-2002-224842В плане
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbi
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %netscape · communicator31 дек. 2002 г.
- CVE-2007-392441В плане
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered
КритическаяCVSS 9,3Эксплойта нетEPSS 14 %microsoft · internet explorer20 июл. 2007 г.
- CVE-2000-057741В плане
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a ..
КритическаяCVSS 10,0Proof of conceptEPSS 5 %netscape · professional services ftpserver21 июн. 2000 г.
- CVE-2000-107441В плане
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser acc
КритическаяCVSS 10,0Proof of conceptEPSS 4 %netscape · iplanet ical11 дек. 2000 г.
- CVE-1999-085341В плане
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Au
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %netscape · enterprise server1 дек. 1999 г.
- CVE-2000-107141В плане
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %netscape · iplanet ical11 дек. 2000 г.
- CVE-2000-096141В плане
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST co
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %netscape · messaging server19 дек. 2000 г.
- CVE-2000-030841В плане
Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 all
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %netscape · enterprise server12 мар. 2001 г.
- CVE-2000-071140В плане
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attacker
ВысокаяCVSS 7,5Proof of conceptEPSS 34 %netscape · communicator20 окт. 2000 г.
- CVE-2000-107640В плане
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %netscape · directory server11 дек. 2000 г.
- CVE-1999-004538Наблюдать
List of arbitrary files on Web host via nph-test-cgi script.
ВысокаяCVSS 7,5Proof of conceptEPSS 26 %apache · http server10 дек. 1996 г.
- CVE-2004-082637Наблюдать
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modif
ВысокаяCVSS 7,5Эксплойта нетEPSS 23 %netscape · certificate server31 дек. 2004 г.
- CVE-2006-425335Наблюдать
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly e
ВысокаяCVSS 7,6Proof of conceptEPSS 15 %mozilla · firefox21 авг. 2006 г.
- CVE-1999-001234Наблюдать
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
ВысокаяCVSS 7,0Эксплойта нетEPSS 19 %microsoft · frontpage6 февр. 1998 г.
- CVE-2007-404233Наблюдать
Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%0
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %netscape · navigator27 июл. 2007 г.
- CVE-2001-059633Наблюдать
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascr
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %netscape · communicator2 авг. 2001 г.
- CVE-1999-023932Наблюдать
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %netscape · fasttrack server1 янв. 1998 г.
- CVE-2001-026232Наблюдать
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %netscape · smartdownload2 июл. 2001 г.
- CVE-1999-053732Наблюдать
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, J
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %netscape · communicator1 апр. 1998 г.
- CVE-2002-109131Наблюдать
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mozilla · mozilla4 окт. 2002 г.