CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. | 7.5 |
|||
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file. | 5 |
|||
Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL. | 5 |
|||
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump. | 5 |
|||
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure. | 10 |
|||
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL. | 5 |
|||
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. | 7.5 |
|||
Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch. | 5 |
|||
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake. | 5 |
|||
Information from SSL-encrypted sessions via PKCS #1. | 5 |
|||
Netscape Enterprise servers may list files through the PageServices query. | 5 |