This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Netscape First view 2005-12-09
Product Navigator Last view 2009-07-20
Version 6 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:netscape:navigator

Activity : Overall

Related : CVE

  Date Alert Description
4.3 2009-07-20 CVE-2009-2542

Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

4 2006-06-07 CVE-2006-2894

Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

5 2005-12-09 CVE-2005-4134

Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox. Also, it has been independently reported that Netscape 8.1 does not have this issue.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-399 Resource Management Errors
50% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
56260 Netscape Select Object Length Property Handling Memory Consumption DoS
26178 Multiple Multiple Browsers OnKey* Keystroke Event File Upload
22892 Mozilla Multiple Products Web Page Title Processing Overflow DoS
21533 Multiple Browser Large History Entry DoS

OpenVAS Exploits

id Description
2009-10-10 Name : SLES9: Security update for Mozilla
File : nvt/sles9p5018527.nasl
2009-07-29 Name : Netscape 'select()' Object Denial Of Service Vulnerability (Linux)
File : nvt/secpod_netscape_select_obj_dos_vuln_lin.nasl
2009-07-29 Name : Netscape 'select()' Object Denial Of Service Vulnerability (Win)
File : nvt/secpod_netscape_select_obj_dos_vuln_win.nasl
2009-04-09 Name : Mandriva Update for mozilla-firefox MDKSA-2007:202 (mozilla-firefox)
File : nvt/gb_mandriva_MDKSA_2007_202.nasl
2009-03-23 Name : Ubuntu Update for firefox vulnerabilities USN-535-1
File : nvt/gb_ubuntu_USN_535_1.nasl
2009-03-23 Name : Ubuntu Update for mozilla-thunderbird, thunderbird vulnerabilities USN-536-1
File : nvt/gb_ubuntu_USN_536_1.nasl
2009-02-27 Name : Fedora Update for firefox FEDORA-2007-2664
File : nvt/gb_fedora_2007_2664_firefox_fc7.nasl
2009-01-28 Name : SuSE Update for MozillaFirefox,mozilla,seamonkey SUSE-SA:2007:057
File : nvt/gb_suse_2007_057.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200604-12 (mozilla-firefox)
File : nvt/glsa_200604_12.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200604-18 (mozilla)
File : nvt/glsa_200604_18.nasl
2008-01-17 Name : Debian Security Advisory DSA 1044-1 (mozilla-firefox)
File : nvt/deb_1044_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1046-1 (mozilla)
File : nvt/deb_1046_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1051-1 (mozilla-thunderbird)
File : nvt/deb_1051_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1392-1 (xulrunner)
File : nvt/deb_1392_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1396-1 (icedove)
File : nvt/deb_1396_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 1401-1 (iceape)
File : nvt/deb_1401_1.nasl

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2009-04-23 Name: The remote Mandrake Linux host is missing one or more security updates.
File: mandrake_MDKSA-2007-202.nasl - Type: ACT_GATHER_INFO
2007-12-21 Name: A web browser on the remote host is prone to multiple flaws.
File: mozilla_firefox_108.nasl - Type: ACT_GATHER_INFO
2007-12-13 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_MozillaFirefox-4570.nasl - Type: ACT_GATHER_INFO
2007-11-10 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-536-1.nasl - Type: ACT_GATHER_INFO
2007-11-10 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-535-1.nasl - Type: ACT_GATHER_INFO
2007-11-06 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1401.nasl - Type: ACT_GATHER_INFO
2007-11-06 Name: The remote Fedora host is missing a security update.
File: fedora_2007-2664.nasl - Type: ACT_GATHER_INFO
2007-10-30 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1396.nasl - Type: ACT_GATHER_INFO
2007-10-26 Name: The remote openSUSE host is missing a security update.
File: suse_seamonkey-4596.nasl - Type: ACT_GATHER_INFO
2007-10-25 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1392.nasl - Type: ACT_GATHER_INFO
2007-10-25 Name: The remote openSUSE host is missing a security update.
File: suse_seamonkey-4594.nasl - Type: ACT_GATHER_INFO
2007-10-24 Name: The remote openSUSE host is missing a security update.
File: suse_MozillaFirefox-4572.nasl - Type: ACT_GATHER_INFO
2007-10-24 Name: A web browser on the remote host is prone to multiple flaws.
File: seamonkey_115.nasl - Type: ACT_GATHER_INFO
2007-10-24 Name: The remote openSUSE host is missing a security update.
File: suse_MozillaFirefox-4574.nasl - Type: ACT_GATHER_INFO
2007-10-19 Name: The remote Windows host contains a web browser that is affected by multiple v...
File: mozilla_firefox_2008.nasl - Type: ACT_GATHER_INFO
2007-02-18 Name: The remote host is missing Sun Security Patch number 120671-08
File: solaris9_120671.nasl - Type: ACT_GATHER_INFO
2007-02-18 Name: The remote host is missing Sun Security Patch number 120671-08
File: solaris8_120671.nasl - Type: ACT_GATHER_INFO
2006-12-16 Name: The remote Mandrake Linux host is missing one or more security updates.
File: mandrake_MDKSA-2006-143.nasl - Type: ACT_GATHER_INFO
2006-12-06 Name: The remote host is missing Sun Security Patch number 120672-08
File: solaris9_x86_120672.nasl - Type: ACT_GATHER_INFO
2006-12-06 Name: The remote host is missing Sun Security Patch number 120672-08
File: solaris8_x86_120672.nasl - Type: ACT_GATHER_INFO
2006-11-06 Name: The remote host is missing Sun Security Patch number 119115-36
File: solaris10_119115.nasl - Type: ACT_GATHER_INFO
2006-11-06 Name: The remote host is missing Sun Security Patch number 119116-35
File: solaris10_x86_119116.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1051.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1046.nasl - Type: ACT_GATHER_INFO
2006-10-14 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-1044.nasl - Type: ACT_GATHER_INFO