Search: "netscape"

129 CVEs found

The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.

Published: 1996-03-01
Products: 2
Vendors:
netscape sun

JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.

Published: 1997-07-08
Products: 5
Vendors:
netscape microsoft
CVE-1999-1262
5.1 MEDIUM

Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote a...

Published: 1997-08-01
Products: 5
Vendors:
netscape

Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.

Published: 1998-01-01
Products: 1
Vendors:
netscape

A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.

Published: 1998-04-01
Products: 2
Vendors:
netscape microsoft
CVE-1999-0269
5.0 MEDIUM

Netscape Enterprise servers may list files through the PageServices query.

Published: 1998-08-01
Products: 1
Vendors:
netscape
CVE-1999-0479
5.0 MEDIUM

Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.

Published: 1999-03-01
Products: 2
Vendors:
hp netscape

talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.

Published: 1999-03-18
Products: 1
Vendors:
netscape
CVE-1999-0425
6.4 MEDIUM

talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.

Published: 1999-03-18
Products: 1
Vendors:
netscape

The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.

Published: 1999-05-01
Products: 1
Vendors:
netscape
CVE-1999-0686
5.0 MEDIUM

Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.

Published: 1999-05-07
Products: 2
Vendors:
hp netscape

When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.

Published: 1999-05-24
Products: 3
Vendors:
netscape
CVE-1999-0752
5.0 MEDIUM

Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.

Published: 1999-07-06
Products: 1
Vendors:
netscape
CVE-1999-0809
5.0 MEDIUM

Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page be...

Published: 1999-07-09
Products: 1
Vendors:
netscape
CVE-1999-1130
5.0 MEDIUM

Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command us...

Published: 1999-07-30
Products: 1
Vendors:
netscape
CVE-1999-0685
5.1 MEDIUM

Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.

Published: 1999-09-02
Products: 5
Vendors:
netscape
CVE-1999-0751
5.0 MEDIUM

Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.

Published: 1999-09-13
Products: 2
Vendors:
netscape

Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allo...

Published: 1999-10-05
Products: 3
Vendors:
netscape

Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.

Published: 1999-10-28
Products: 1
Vendors:
netscape
CVE-1999-1532
5.0 MEDIUM

Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.

Published: 1999-10-29
Products: 3
Vendors:
netscape