First published: Fri Oct 13 2000(Updated: )
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netscape Communicator | =4.05 | |
Microsoft Virtual Machine | =3100 | |
Netscape Communicator | =4.04 | |
Netscape Communicator | =4.61 | |
Netscape Communicator | =4.07 | |
Netscape Communicator | =4.73 | |
Netscape Communicator | =4.51 | |
Netscape Communicator | =4.06 | |
Microsoft Virtual Machine | =3200 | |
Netscape Communicator | =4.7 | |
Netscape Communicator | =4.0 | |
Microsoft Virtual Machine | =3300 | |
Netscape Communicator | =4.74 | |
Netscape Communicator | =4.08 | |
Netscape Communicator | =4.6 | |
Microsoft Virtual Machine | =2000 | |
Netscape Communicator | =4.72 | |
Netscape Communicator | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0711 is classified as a moderate severity vulnerability due to its potential for remote exploitation.
To fix CVE-2000-0711, update Netscape Communicator to a patched version or ensure that untrusted applets are not executed.
CVE-2000-0711 affects several versions of Netscape Communicator as well as specific versions of Microsoft Virtual Machine.
Attackers can exploit CVE-2000-0711 to create a malicious server on the victim's system through a malicious applet.
Yes, CVE-2000-0711 has been demonstrated through the malicious applet known as Brown Orifice.