Page 4 of 43 results (0.007 seconds)

CVSS: 5.0EPSS: 0%CPEs: 30EXPL: 2

31 Dec 2002 — Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. • http://alive.znep.com/~marcs/security/mozillacookie/demo.html •

CVSS: 9.8EPSS: 3%CPEs: 2EXPL: 0

31 Dec 2002 — Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel. • http://bugzilla.mozilla.org/show_bug.cgi?id=157202 •

CVSS: 7.5EPSS: 5%CPEs: 36EXPL: 2

31 Dec 2002 — The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message. • https://www.exploit-db.com/exploits/21539 • CWE-20: Improper Input Validation •

CVSS: 8.8EPSS: 5%CPEs: 12EXPL: 0

29 Nov 2002 — Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression. Desbordamiento de búfer basado en el montículo (heap) en Netscape y Mozilla permite a atacantes remotos ejecutar código arbitrario mediante una URL de tipo jar: que referencia a un fichero .jar malformado, lo que desborda un búfer durante la descompresión. • http://bugzilla.mozilla.org/show_bug.cgi?id=157646 •

CVSS: 9.8EPSS: 4%CPEs: 13EXPL: 1

04 Oct 2002 — Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. • http://bugzilla.mozilla.org/show_bug.cgi?id=157989 •

CVSS: 5.0EPSS: 1%CPEs: 10EXPL: 1

18 Jun 2002 — Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 •

CVSS: 9.8EPSS: 3%CPEs: 5EXPL: 1

11 Jun 2002 — Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490 •

CVSS: 7.5EPSS: 0%CPEs: 7EXPL: 0

03 May 2002 — The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. • http://marc.info/?l=bugtraq&m=102017952204097&w=2 •

CVSS: 9.8EPSS: 1%CPEs: 2EXPL: 0

09 Jan 2001 — Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc •

CVSS: 9.8EPSS: 2%CPEs: 2EXPL: 2

24 Nov 1999 — Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file. • http://www.securityfocus.com/archive/1/36306 •