Page 3 of 33 results (0.009 seconds)

CVSS: 7.5EPSS: 1%CPEs: 3EXPL: 0

01 Aug 2002 — The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted site into one frame, and passing the information to the attacker-controlled frame, which is allowed because the document.domain of the two frames matches on the parent domain. • http://marc.info/?l=bugtraq&m=102796732924658&w=2 •

CVSS: 5.0EPSS: 1%CPEs: 10EXPL: 1

18 Jun 2002 — Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 •

CVSS: 9.8EPSS: 3%CPEs: 5EXPL: 1

11 Jun 2002 — Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

03 May 2002 — The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. • http://marc.info/?l=bugtraq&m=102017952204097&w=2 •

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 0

09 Jan 2001 — Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc •

CVSS: 9.1EPSS: 0%CPEs: 2EXPL: 0

12 Jan 2000 — Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. • http://marc.info/?l=bugtraq&m=94790377622943&w=2 •

CVSS: 9.8EPSS: 2%CPEs: 2EXPL: 2

24 Nov 1999 — Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file. • http://www.securityfocus.com/archive/1/36306 •

CVSS: 7.5EPSS: 0%CPEs: 11EXPL: 0

01 Nov 1999 — By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0827 •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

24 May 1999 — When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0762 •

CVSS: 9.8EPSS: 1%CPEs: 13EXPL: 0

01 Mar 1999 — The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages. • http://java.sun.com/pr/1999/03/pr990329-01.html •