CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. NOTE: this product is discontinued. | 6.1 |
Medium |
||
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL. | 5 |
|||
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. | 7.5 |
|||
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake. | 5 |
|||
Netscape Enterprise servers may list files through the PageServices query. | 5 |