Page 2 of 19 results (0.007 seconds)

CVSS: 5.3EPSS: 0%CPEs: 8EXPL: 0

26 May 2000 — Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information. • http://www.cert.org/advisories/CA-2000-08.html •

CVSS: 2.6EPSS: 0%CPEs: 11EXPL: 0

10 May 2000 — Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability. • http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

01 Apr 2000 — A remote attacker can read information from a Netscape user's cache via JavaScript. • http://home.netscape.com/security/notes/jscachebrowsing.html •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

28 Oct 1999 — Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key. • http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

05 Oct 1999 — Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters. • http://marc.info/?l=bugtraq&m=93915331626185&w=2 •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

09 Jul 1999 — Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed". • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0809 •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

24 May 1999 — When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0762 •

CVSS: 4.3EPSS: 21%CPEs: 5EXPL: 0

08 Jul 1997 — JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. • http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html •

CVSS: 7.5EPSS: 3%CPEs: 7EXPL: 1

01 Feb 1997 — The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. • https://www.exploit-db.com/exploits/20568 •