Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Low

CVE-2021-45046

Disclosure Date: December 14, 2021 (last updated October 07, 2023)
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Attacker Value
Unknown

CVE-2008-0917

Disclosure Date: February 22, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2003-1560

Disclosure Date: December 31, 2003 (last updated February 22, 2025)
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
0
Attacker Value
Unknown

CVE-2002-2338

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
0
Attacker Value
Unknown

CVE-2002-2013

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
0
Attacker Value
Unknown

CVE-2000-0087

Disclosure Date: January 12, 2000 (last updated February 22, 2025)
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
0
Attacker Value
Unknown

CVE-1999-1189

Disclosure Date: November 24, 1999 (last updated February 22, 2025)
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
0
Attacker Value
Unknown

CVE-1999-0827

Disclosure Date: November 01, 1999 (last updated February 22, 2025)
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
0
Attacker Value
Unknown

CVE-1999-0762

Disclosure Date: May 24, 1999 (last updated February 22, 2025)
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.
0
Attacker Value
Unknown

CVE-1999-0440

Disclosure Date: March 01, 1999 (last updated February 22, 2025)
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
0