Skip to main content

Vendor/product archive

aol / instant_messenger CVEs

Beta · best-effort

30 CVEs tagged to aol / instant_messenger4 Critical, 7 High, 18 Medium, 1 Low, 0 Unrated.

CVE-2007-5124

Published Sep 27, 2007

The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.5.3.12 and earlier allows remote attackers to execute arbitrary code via unspecified web script or H…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4901

Published Sep 14, 2007

The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web s…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3437

Published Jun 27, 2007

AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application crash) via a malformed header value in a SIP INVITE message, a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3350

Published Jun 22, 2007

AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP INVITE requests.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1904

Published Apr 10, 2007

Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0629

Published Feb 10, 2006

Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denial of service (client crash) and possibly execute arbitrary…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1655

Published May 18, 2005

AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1420

Published May 2, 2005

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2373

Published Dec 31, 2004

The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0636

Published Nov 23, 2004

Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-1503

Published Dec 31, 2003

Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1813

Published Dec 31, 2002

Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1953

Published Dec 31, 2002

Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2169

Published Dec 31, 2002

Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0785

Published Aug 12, 2002

AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0591

Published Jun 18, 2002

Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connectio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0592

Published Jun 18, 2002

AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file tr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0362

Published May 29, 2002

Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1591

Published Apr 8, 2002

AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass int…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0005

Published Jan 31, 2002

Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddG…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-1417

Published Oct 6, 2001

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1418

Published Oct 6, 2001

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1421

Published Oct 6, 2001

AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR t…

CVSS 5.0 · Medium
Buzz score
12.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-1419

Published Oct 2, 2001

AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 30 CVEsPage 1 of 2