CVE-2002-1204: Medium severity Netscape Communicator vulnerability
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the userpref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1204?
CVE-2002-1204 has a medium severity rating as it can expose sensitive user information.
How do I fix CVE-2002-1204?
To mitigate CVE-2002-1204, users should upgrade to a newer, patched version of Netscape Communicator.
What does CVE-2002-1204 exploit?
CVE-2002-1204 exploits the user_pref() function to steal user preferences and sensitive information.
Which versions of Netscape Communicator are affected by CVE-2002-1204?
Netscape Communicator versions 4.6 to 4.78 are affected by CVE-2002-1204.
Can CVE-2002-1204 lead to unauthorized access?
Yes, CVE-2002-1204 can potentially allow attackers to access sensitive user data.