CVE-2002-1766

Netscape Communicator - Buffer Overflow via Font Tag Face Attribute

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1766. PoCs published by S[h]iff.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow in Netscape Composer when editing an HTML page with a Font Face field exceeding 190 characters. The overflow can lead to memory corruption and potential arbitrary code execution.

Description

Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.

Exploits (1)

exploitdb WORKING POC VERIFIED
by S[h]iff · htmldosmultiple
https://www.exploit-db.com/exploits/21544

This exploit demonstrates a buffer overflow in Netscape Composer when editing an HTML page with a Font Face field exceeding 190 characters. The overflow can lead to memory corruption and potential arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Netscape Composer (Linux platform)
No auth needed
Prerequisites: Victim must open the malicious HTML file in Netscape Composer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/276876
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5010
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/9355

Scores

EPSS 0.0101
EPSS Percentile 58.5%

Details

Status published
Products (1)
netscape/communicator 4.77
Published Dec 31, 2002
Tracked Since Feb 18, 2026