← Vulnerability feed

Vulnerability record · CVE-2002-2248 · published 31 December 2002

CVE-2002-2248: Netscape communicator memory buffer overflow vulnerability

Netscape · Communicator

Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.

10.0 CVSS 2.0 High EPSS 5.8% · top 7.2% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-2248 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2002-0593Mozilla vulnerabilityBuffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbit…EPSS 3.5%7.5CVE-2001-0596Netscape communicator vulnerabilityNetscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.EPSS 8.7%7.5CVE-2000-1187Netscape communicator vulnerabilityBuffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a…EPSS 2.6%7.5CVE-2000-0711Microsoft virtual machine vulnerabilityNetscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to crea…EPSS 34%7.5CVE-1999-1189Netscape communicator vulnerabilityBuffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possib…EPSS 2.5%7.5CVE-1999-1357Netscape communicator vulnerabilityNetscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and…EPSS 2.0%7.5CVE-1999-0440Netscape communicator vulnerabilityThe byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.EPSS 3.6%7.5CVE-1999-0537Microsoft internet explorer vulnerabilityA configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript…EPSS 6.0%

Source: NIST National Vulnerability Database (record CVE-2002-2248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.