CVE-1999-0869: Low severity Netscape Navigator vulnerability
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Internet Explorer (3.x - 4.01)from your environment.Uninstall or stop using Internet Explorer versions 3.x through 4.01. If removal is not immediately possible, avoid using these browser versions to access untrusted or external websites until a vendor fix is available.
- Remove
Remove
Netscape Navigatorfrom your environment.Uninstall or stop using Netscape Navigator. If removal is not immediately possible, avoid using this browser to access untrusted or external websites until a vendor-provided remediation is available.
- Compensating control
Restrict web access to trusted sites only (via firewall, proxy, or URL-filtering) and require users to use alternative, up-to-date browsers for web access to mitigate frame-spoofing risk.
- Operational
Monitor vendor security advisories for Internet Explorer and Netscape Navigator for any released fixes or patches and apply them as soon as they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0869?
CVE-1999-0869 has been classified with a moderate severity level due to its potential for frame spoofing attacks.
How do I fix CVE-1999-0869?
To fix CVE-1999-0869, update to a more secure version of Internet Explorer that addresses this vulnerability.
What versions of Internet Explorer are affected by CVE-1999-0869?
CVE-1999-0869 affects Internet Explorer versions 3.x through 4.01.
Can CVE-1999-0869 affect other browsers?
While CVE-1999-0869 specifically mentions Internet Explorer, similar frame spoofing techniques may affect other browsers such as Netscape Navigator.
How can I protect myself from CVE-1999-0869 exploits?
To protect against CVE-1999-0869 exploits, avoid using outdated browsers and ensure you have the latest security updates installed.