CVE-2002-1204
https://notcve.org/view.php?id=CVE-2002-1204
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name. Netscape Communicator 4.x permite a atacantes usar un enlace para robar las preferencias de un usuario, incluyendo información potencialmente sensible como historia de URLs, direcciones de correo electrónico, y posiblemente sus contraseñas, mediante la redefinición de la función user_pref() y accediendo al fichero prefs.js, que está almacenado en un directorio con un nombre predecible. • http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0081.html http://www.idefense.com/advisory/11.19.02c.txt http://www.iss.net/security_center/static/10655.php http://www.securityfocus.com/bid/6215 •
CVE-2001-0921
https://notcve.org/view.php?id=CVE-2001-0921
Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext. • http://marc.info/?l=bugtraq&m=100638816318705&w=2 http://www.osvdb.org/5524 http://www.securityfocus.com/bid/3565 https://exchange.xforce.ibmcloud.com/vulnerabilities/7593 •
CVE-2001-0596 – Netscape Navigator 4.0.8 - 'about:' Domain Information Disclosure
https://notcve.org/view.php?id=CVE-2001-0596
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript. • https://www.exploit-db.com/exploits/20791 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000393 http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-014-01 http://marc.info/?l=bugtraq&m=98685237415117&w=2 http://www.debian.org/security/2001/dsa-051 http://www.osvdb.org/5579 http://www.redhat.com/support/errata/RHSA-2001-046.html http://www.securityfocus.com/bid/2637 https://exchange.xforce.ibmcloud.com/vulnerabilities/6344 •
CVE-2000-1187
https://notcve.org/view.php?id=CVE-2000-1187
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000344 http://lists.suse.com/archives/suse-security-announce/2000-Nov/0005.html http://marc.info/?l=bugtraq&m=97500270012529&w=2 http://www.osvdb.org/7207 http://www.redhat.com/support/errata/RHSA-2000-109.html https://exchange.xforce.ibmcloud.com/vulnerabilities/5542 •
CVE-2000-0676 – Netscape Communicator 4.x - URL Read
https://notcve.org/view.php?id=CVE-2000-0676
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice. • https://www.exploit-db.com/exploits/20140 ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc http://archives.neohapsis.com/archives/bugtraq/2000-08/0019.html http://archives.neohapsis.com/archives/bugtraq/2000-08/0115.html http://archives.neohapsis.com/archives/bugtraq/2000-08/0236.html http://archives.neohapsis.com/archives/bugtraq/2000-08/0265.html http://www.calderasystems.com/support/security/advisories/CSSA-2000-027.1.txt http://www.cert.org/advi •