CVE-1999-0790: Low severity Netscape Communicator vulnerability
A remote attacker can read information from a Netscape user's cache via JavaScript.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable JavaScript in Netscape Communicator to prevent remote scripts from reading the browser cache.
Netscape Communicator javascript_enabled = false - Compensating control
Use a network-level content filter/proxy or browser extension to block or strip JavaScript from untrusted or untrusted-origin websites to mitigate remote script access to the cache.
- Operational
Clear the Netscape Communicator browser cache to remove potentially exposed sensitive data.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0790?
CVE-1999-0790 is considered a moderate severity vulnerability due to its potential to expose sensitive user information.
How do I fix CVE-1999-0790?
To fix CVE-1999-0790, users should upgrade to a later version of Netscape Communicator that is no longer vulnerable.
Who is affected by CVE-1999-0790?
Users of Netscape Communicator version 4.0 are primarily affected by CVE-1999-0790.
What type of attack is CVE-1999-0790?
CVE-1999-0790 pertains to a remote attack that exploits JavaScript to access information in a user's cache.
Can I secure my system against CVE-1999-0790?
To secure your system against CVE-1999-0790, avoid using vulnerable versions of Netscape Communicator and employ modern, supported web browsers.