Skip to main content

Vendor/product archive

cerulean_studios / trillian CVEs

Beta · best-effort

31 CVEs tagged to cerulean_studios / trillian8 Critical, 8 High, 15 Medium, 0 Low, 0 Unrated.

CVE-2012-5824

Published Nov 4, 2012

Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows m…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4831

Published Apr 29, 2010

Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle atta…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2409

Published May 23, 2008

Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2008

Published Apr 29, 2008

Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arb…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3832

Published Jul 17, 2007

Buffer overflow in the AOL Instant Messenger (AIM) protocol handler in AIM.DLL in Cerulean Studios Trillian allows remote attackers to execute arbitrary code via a malformed aim:…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3833

Published Jul 17, 2007

The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrate…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3305

Published Jun 21, 2007

Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execute arbitrary code via a message sent through the MSN protocol, or possib…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-2479

Published May 3, 2007

Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which g…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0543

Published Feb 4, 2006

Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequenc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3141

Published Oct 5, 2005

Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a reverse direct connection from a different client, as demonstrated using LICQ.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0874

Published May 2, 2005

Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a lon…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0875

Published May 2, 2005

Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1666

Published Dec 31, 2004

Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0520

Published Aug 18, 2003

Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1485

Published Apr 2, 2003

The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C".

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1486

Published Apr 2, 2003

Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1487

Published Apr 2, 2003

The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1488

Published Apr 2, 2003

The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2155

Published Dec 31, 2002

Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2