JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
https://euvd.enisa.europa.eu/vulnerability/EUVD-1999-0031
http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html