// For flags

CVE-2002-1204

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

Netscape Communicator 4.x permite a atacantes usar un enlace para robar las preferencias de un usuario, incluyendo información potencialmente sensible como historia de URLs, direcciones de correo electrónico, y posiblemente sus contraseñas, mediante la redefinición de la función user_pref() y accediendo al fichero prefs.js, que está almacenado en un directorio con un nombre predecible.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2002-10-14 CVE Reserved
  • 2002-11-21 CVE Published
  • 2024-08-08 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.6
Search vendor "Netscape" for product "Communicator" and version "4.6"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.7
Search vendor "Netscape" for product "Communicator" and version "4.7"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.61
Search vendor "Netscape" for product "Communicator" and version "4.61"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.72
Search vendor "Netscape" for product "Communicator" and version "4.72"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.73
Search vendor "Netscape" for product "Communicator" and version "4.73"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.74
Search vendor "Netscape" for product "Communicator" and version "4.74"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.75
Search vendor "Netscape" for product "Communicator" and version "4.75"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.76
Search vendor "Netscape" for product "Communicator" and version "4.76"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.77
Search vendor "Netscape" for product "Communicator" and version "4.77"
-
Affected
Netscape
Search vendor "Netscape"
Communicator
Search vendor "Netscape" for product "Communicator"
4.78
Search vendor "Netscape" for product "Communicator" and version "4.78"
-
Affected