CVE detail
CVE-2002-1204 — CVE-2002-1204
Published 2002-11-29 · Modified 2026-06-16 · Vendor netscape · Product communicator · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0132
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a predictable name.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References