7.5
CVSSv2

CVE-2000-0711

Published: 20/10/2000 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote malicious users to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.

Vulnerable Product Search on Vulmon Subscribe to Product

netscape communicator 4.05

microsoft virtual machine 3100

netscape communicator 4.04

netscape communicator 4.61

netscape communicator 4.07

netscape communicator 4.73

netscape communicator 4.51

netscape communicator 4.06

microsoft virtual machine 3200

netscape communicator 4.7

netscape communicator 4.0

microsoft virtual machine 3300

netscape communicator 4.74

netscape communicator 4.08

netscape communicator 4.6

microsoft virtual machine 2000

netscape communicator 4.72

netscape communicator 4.5

Exploits

source: wwwsecurityfocuscom/bid/1545/info A set of flaws in multiple vendors' Java implementation allows a malicious applet to open a listening socket to accept network connections against the security policy Java applications use the javanetServerSocket class to create a listening network socket on which to accept network connections ...