CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692. |
2Mozilla Netscape4Firefox GeckbNavigator+1 moreApr 23, 2026 Jul 8, 2008 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the ba...Show more |
2Microsoft Netscape2Internet Explorer NavigatorApr 23, 2026 Jul 27, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (...Show more |
2Microsoft Netscape2Internet Explorer NavigatorApr 23, 2026 Jul 21, 2007 N/A· v4 N/A· v3 9.3 HIGH· v2 Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute...Show more |
4Adobe MozillaNetscape+1 more4Acrobat Reader FirefoxNavigator+1 moreApr 23, 2026 Mar 10, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier th...Show more |
The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing...Show more |
3K Meleon Project MozillaNetscape3Firefox K MeleonNavigatorApr 16, 2026 Aug 21, 2006 N/A· v4 N/A· v3 7.6 HIGH· v2 Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply ne...Show more |
2Mozilla Netscape4Firefox Mozilla SuiteNavigator+1 moreApr 16, 2026 Jun 7, 2006 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by t...Show more |
2Mozilla Netscape3Firefox Mozilla SuiteNavigatorApr 16, 2026 May 26, 2006 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain informati...Show more |
3K Meleon Project MozillaNetscape3Firefox K MeleonNavigatorApr 16, 2026 Apr 20, 2006 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containin...Show more |
3K Meleon Project MozillaNetscape4Firefox K MeleonMozilla Suite+1 moreApr 16, 2026 Dec 9, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is r...Show more |
2Mozilla Netscape3Firefox MozillaNavigatorApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine,...Show more |
2Mozilla Netscape3Firefox MozillaNavigatorApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1." |
2Mozilla Netscape3Firefox MozillaNavigatorApr 16, 2026 May 2, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambd...Show more |
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as d...Show more |
2Mozilla Netscape3Firefox MozillaNavigatorApr 16, 2026 Dec 31, 2004 N/A· v4 N/A· v3 2.6 LOW· v2 The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from...Show more |
4Conectiva MozillaNetscape+1 more10Enterprise Linux Enterprise Linux DesktopFedora Core+7 moreApr 16, 2026 Dec 31, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that tr...Show more |
5Conectiva MozillaNetscape+2 more10Enterprise Linux Enterprise Linux DesktopFedora Core+7 moreApr 16, 2026 Sep 14, 2004 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and...Show more |
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code. |
Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the...Show more |