First published: Fri Aug 01 1997(Updated: )
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Communicator | =4.07 | |
Netscape Communicator | =4.06 | |
Netscape Communicator | =4.01 | |
Netscape Communicator | =4.08 | |
Netscape Communicator | =4.5 | |
=4.01 | ||
=4.5 | ||
=4.06 | ||
=4.07 | ||
=4.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1262 is classified with a moderate severity level due to the potential for unauthorized access by remote attackers.
To remediate CVE-1999-1262, users should update to a patched version of Netscape Communicator that corrects the applet security flaw.
CVE-1999-1262 affects Netscape Communicator versions 4.01, 4.05, 4.06, 4.07, and 4.08.
CVE-1999-1262 allows applets to connect to unauthorized hosts, which can lead to data breaches or system compromises.
Disabling Java applets or restricting applet usage in Netscape Communicator can serve as a temporary workaround for CVE-1999-1262.