CVE-2000-0087 describes a vulnerability in the Netscape Mail Notification (nsnotify) utility within Netscape Communicator and Navigator. This flaw allows a remote attacker to intercept usernames and passwords in plaintext due to the utility's failure to enforce SSL for IMAP connections, even when configured by the user. The vulnerability carries a CVSS score of 5.0 (Medium), indicating a network-based attack with low complexity and potential for partial confidentiality impact. There is no authentication required for an attacker to exploit this weakness. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit tools like Metasploit or ExploitDB entries. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.7CPE matchmatch criteria | cpe:2.3:a:netscape:communicator:4.7:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:netscape:navigator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.