VendorsNetscapecommunicator4.05
Vulnerabilities

Netscape Communicator 4.05

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2000-0711
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
Published 2000-10-13 · Modified
7.51 PoCEPSS 0.335
CVE-1999-0174
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Published 1999-09-29 · Modified
6.41 PoCEPSS 0.069
CVE-2000-0676
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.205
CVE-2000-0655
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.127
CVE-2000-0406
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
Published 2000-07-12 · Modified
2.6EPSS 0.010