vendor:
Netscape Communicator
by:
Steve Fewer
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Netscape Communicator
Affected Version From: Netscape Communicator 4.5
Affected Version To: Netscape Communicator 4.5
Patch Exists: NO
Related CWE: CVE-1999-1266
CPE: a:netscape:communicator:4.5
Platforms Tested: Windows 98
1999
Netscape Communicator 4.5 Unchecked Buffer Code Execution
Netscape Communicator 4.5 has an unchecked buffer, through which code can be injected for execution via the prefs.js preferences file. This could be exploited locally to run arbitrary code at the privilege level of the current user.
Mitigation:
Upgrade to a newer version of Netscape Communicator.