Vulnerability Name:

CVE-1999-0685 (CCN-3243)

Assigned:1999-09-02
Published:1999-09-02
Updated:2008-09-09
Summary:Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
CVSS v3 Severity:5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
5.1 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Thu, 2 Sep 1999 23:45:50 +0900
Netscape communicator 4.06J, 4.5J-4.6J, 4.61e Buffer Overflow

Source: MITRE
Type: CNA
CVE-1999-0685

Source: CCN
Type: OSVDB ID: 1063
Netscape Communicator pluginspage Option EMBED Tag Overflow

Source: BID
Type: UNKNOWN
618

Source: CCN
Type: BID-618
Netscape Communicator EMBED Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
netscape-embed-bo(3243)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:netscape:communicator:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.06:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.6:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.51:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.61:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:netscape:communicator:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.51:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.6:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.61:*:*:*:*:*:*:*
  • OR cpe:/a:netscape:communicator:4.06:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    netscape communicator 4.5
    netscape communicator 4.06
    netscape communicator 4.6
    netscape communicator 4.51
    netscape communicator 4.61
    netscape communicator 4.5
    netscape communicator 4.51
    netscape communicator 4.6
    netscape communicator 4.61
    netscape communicator 4.06