CVE-1999-0892

CVSS 2.0 Score 4.6 of 10 (medium)

Details

Published Dec 24, 1999
Updated: Nov 20, 2024

Summary

CVE-1999-0892 is a buffer overflow vulnerability affecting Netscape Communicator versions prior to 4.7. This issue arises due to a dynamic font whose length field is incorrectly specified, causing data to be written beyond the intended buffer boundary. An attacker could exploit this vulnerability by crafting a maliciously sized font and convincing a user to view a specially crafted webpage, potentially leading to arbitrary code execution or a denial-of-service condition. This flaw presents a serious security risk, as it allows an attacker to gain unauthorized access or control over an affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Netscape Communicator

Affected Vendors

  • Netscape