Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netscape

First CVE: Mar 1, 1996Active for: 30 yearsTotal CVEs: 120
39.9
VTI Score
Medium

Netscape's vulnerability footprint spans a historically significant but now legacy portfolio of web browsers, email clients, and server products that dominated internet infrastructure in the 1990s and early 2000s. Although the vendor ceased active development decades ago, its disclosures remain among the most represented in the historical CVE record, reflecting the product's former ubiquity and the intensive security scrutiny applied to internet-critical software of that era. The recurring weakness classes—including improper input validation, exposure of sensitive information, authentication bypasses through spoofing, and case-sensitivity handling flaws—are characteristic of web client and server software from that period, where memory-safety and input-handling practices were less mature. Public exploit code has frequently accompanied Netscape disclosures, reflecting both the historical interest in these now-superseded products and the relative ease of weaponizing web-client and protocol-parsing flaws. Defenders should treat Netscape products as obsolete and prioritize their removal from any active infrastructure; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
120
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netscape over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 1996
30 years ago
Most Recent CVE
Jan 31, 2019
2,731 days ago

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (120 CVEs).

120 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-1999-0043CRITICAL
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Dec 4, 19969.855NONO
CVE-1999-0005HIGH
Arbitrary command execution via IMAP buffer overflow in authenticate command.
Jul 20, 199810.048NOYES
CVE-2000-0711HIGH
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's sys
Oct 20, 20007.546NOYES
CVE-1999-0045HIGH
List of arbitrary files on Web host via nph-test-cgi script.
Dec 10, 19967.543NOYES
CVE-2004-0722HIGH
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute
Aug 18, 200410.041NOYES
CVE-2001-0596HIGH
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.
Aug 2, 20017.538NOYES
CVE-2000-1074HIGH
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating
Dec 11, 200010.036NOYES
CVE-2000-0577HIGH
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Jun 21, 200010.036NOYES
CVE-2006-4253HIGH
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javas
Aug 21, 20067.635NOYES
CVE-2007-1377MEDIUM
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via
Mar 10, 20075.034NOYES
View all 120 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products120 CVEs
12%
48%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (3.3%)
Unknown116 (96.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (2.5%)
High1 (0.8%)
Unknown116 (96.7%)
User Interaction
None3 (2.5%)
Unknown116 (96.7%)
Required1 (0.8%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (3.3%)
Unknown116 (96.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (120 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
38 CVEs
31.7% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netscape.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netscape — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netscape's Products

View all 2 CNAs →

Top CWEs