CVE Vulnerabilities

CVE-2002-1204

Published: Nov 29, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Netscape Communicator 4.x allows attackers to use a link to steal a users preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.

Affected Software

NameVendorStart VersionEnd Version
CommunicatorNetscape4.6 (including)4.6 (including)
CommunicatorNetscape4.7 (including)4.7 (including)
CommunicatorNetscape4.61 (including)4.61 (including)
CommunicatorNetscape4.72 (including)4.72 (including)
CommunicatorNetscape4.73 (including)4.73 (including)
CommunicatorNetscape4.74 (including)4.74 (including)
CommunicatorNetscape4.75 (including)4.75 (including)
CommunicatorNetscape4.76 (including)4.76 (including)
CommunicatorNetscape4.77 (including)4.77 (including)
CommunicatorNetscape4.78 (including)4.78 (including)

References