Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
2000-10-20T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microsoft | virtual_machine | 2000 | Yes |
Application | microsoft | virtual_machine | 3100 | Yes |
Application | microsoft | virtual_machine | 3200 | Yes |
Application | microsoft | virtual_machine | 3300 | Yes |
Application | netscape | communicator | 4.0 | Yes |
Application | netscape | communicator | 4.04 | Yes |
Application | netscape | communicator | 4.05 | Yes |
Application | netscape | communicator | 4.5 | Yes |
Application | netscape | communicator | 4.06 | Yes |
Application | netscape | communicator | 4.6 | Yes |
Application | netscape | communicator | 4.07 | Yes |
Application | netscape | communicator | 4.7 | Yes |
Application | netscape | communicator | 4.08 | Yes |
Application | netscape | communicator | 4.51 | Yes |
Application | netscape | communicator | 4.61 | Yes |
Application | netscape | communicator | 4.72 | Yes |
Application | netscape | communicator | 4.73 | Yes |
Application | netscape | communicator | 4.74 | Yes |