The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.
Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.
Netscape Enterprise servers may list files through the PageServices query.
Arbitrary command execution via IMAP buffer overflow in authenticate command.
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violat…
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.