CVE-2000-0676 describes a vulnerability in Netscape Communicator and Navigator versions 4.04 through 4.74, allowing remote attackers to read arbitrary local files. This is achieved by a malicious Java applet opening a connection to a URL using various protocols like "file," "http," "https," and "ftp." The vulnerability has a CVSS score of 5.0 (MEDIUM), indicating a network-based attack with low complexity that can lead to partial confidentiality impact. While there is an ExploitDB entry, there is no evidence of active exploitation, Metasploit modules, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:a:netscape:communicator:4.0:*:*:*:*:*:*:* | ||
4.04CPE matchmatch criteria | cpe:2.3:a:netscape:communicator:4.04:*:*:*:*:*:*:* | ||
4.05CPE matchmatch criteria | cpe:2.3:a:netscape:communicator:4.05:*:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:a:netscape:communicator:4.5:*:*:*:*:*:*:* | ||
4.5_betaCPE matchmatch criteria | cpe:2.3:a:netscape:communicator:4.5_beta:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.