CVE-2002-0591 – AOL Instant Messenger 4.x - Arbitrary File Creation
https://notcve.org/view.php?id=CVE-2002-0591
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename. • https://www.exploit-db.com/exploits/21386 http://archives.neohapsis.com/archives/bugtraq/2002-04/0203.html http://www.iss.net/security_center/static/8870.php http://www.securityfocus.com/bid/4526 •
CVE-2002-0592
https://notcve.org/view.php?id=CVE-2002-0592
AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user. • http://online.securityfocus.com/archive/1/269006 http://www.securityfocus.com/bid/4574 https://exchange.xforce.ibmcloud.com/vulnerabilities/8931 •
CVE-2002-0005 – AOL Instant Messenger 4.x - Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-2002-0005
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame). Desbordamiento de buffer en AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, y otras versiones permite a atacantes remotos ejecutar código arbitrario mediante un argumento largo en una petición de juegos (AddGame). • https://www.exploit-db.com/exploits/21196 http://marc.info/?l=ntbugtraq&m=100998295512885&w=2 http://www.kb.cert.org/vuls/id/907819 http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0201&L=ntbugtraq&F=P&S=&P=198 http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0201&L=ntbugtraq&F=P&S=&P=72 http://www.securityfocus.com/archive/1/247944 http://www.securityfocus.com/bid/3769 https://exchange.xforce.ibmcloud.com/vulnerabilities/7743 •
CVE-2001-1421
https://notcve.org/view.php?id=CVE-2001-1421
AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag. • http://www.kb.cert.org/vuls/id/530299 http://www.kb.cert.org/vuls/id/JARL-569MD7 http://www.securityfocus.com/archive/1/218920 http://www.securityfocus.com/archive/1/247707 http://www.securityfocus.com/bid/3756 https://exchange.xforce.ibmcloud.com/vulnerabilities/7757 •
CVE-2001-1419
https://notcve.org/view.php?id=CVE-2001-1419
AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments. • http://archives.neohapsis.com/archives/bugtraq/2001-10/0014.html http://www.kb.cert.org/vuls/id/507771 http://www.kb.cert.org/vuls/id/JARL-56TPTN http://www.securityfocus.com/archive/1/247707 http://www.securityfocus.com/bid/3398 https://exchange.xforce.ibmcloud.com/vulnerabilities/7233 •