Communicator

Vendor:

First CVE: Feb 1, 1997 · Active for 29 years

35
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Communicator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 1997
29 years ago
Most Recent CVE
Dec 31, 2002
8,606 days ago

CVE Severity & Scoring

Communicator35 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown35 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown35 (100.0%)
User Interaction
None0 (0.0%)
Unknown35 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown35 (100.0%)

Top CVEs

Signals from CVEs in this product scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's sys
Oct 20, 20007.546NOYES
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.
Aug 2, 20017.538NOYES
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http",
Oct 20, 20005.031NOYES
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Feb 1, 19976.430NOYES
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message co
Dec 31, 20025.029NOYES
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal fiel
Jul 25, 20005.027NOYES
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the
Dec 31, 200210.026NONO
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
Sep 2, 19995.123NOYES
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.
Apr 1, 19987.523NONO
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.
Dec 31, 20024.621NOYES

Exploit Exposure

Signals from CVEs in this product scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
25.7% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (35 CVEs).

Media Mentions

Signals from CVEs in this product scope (35 CVEs).

Top CNAs Publishing CVEs For Communicator

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.115.01.1%00
6.117.53.5%00
4.x12.61.5%00
4.7928.23.9%00
4.7846.62.7%00
4.7766.02.6%02
4.7656.32.9%01
4.7556.32.9%01
4.7476.39.8%03
4.73105.88.3%05
4.72115.57.6%05
4.7145.55.0%04
4.61125.47.1%06
4.6145.36.7%07
4.5_beta44.49.0%02
4.51135.77.2%07
4.5175.45.8%07
4.425.02.8%01
4.0865.412.3%04
4.0785.210.2%05