Page 2 of 10 results (0.014 seconds)

CVSS: 5.0EPSS: 3%CPEs: 9EXPL: 3

Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename. • https://www.exploit-db.com/exploits/21386 http://archives.neohapsis.com/archives/bugtraq/2002-04/0203.html http://www.iss.net/security_center/static/8870.php http://www.securityfocus.com/bid/4526 •

CVSS: 7.5EPSS: 1%CPEs: 27EXPL: 0

AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user. • http://online.securityfocus.com/archive/1/269006 http://www.securityfocus.com/bid/4574 https://exchange.xforce.ibmcloud.com/vulnerabilities/8931 •

CVSS: 10.0EPSS: 15%CPEs: 8EXPL: 3

Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame). Desbordamiento de buffer en AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, y otras versiones permite a atacantes remotos ejecutar código arbitrario mediante un argumento largo en una petición de juegos (AddGame). • https://www.exploit-db.com/exploits/21196 http://marc.info/?l=ntbugtraq&m=100998295512885&w=2 http://www.kb.cert.org/vuls/id/907819 http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0201&L=ntbugtraq&F=P&S=&P=198 http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0201&L=ntbugtraq&F=P&S=&P=72 http://www.securityfocus.com/archive/1/247944 http://www.securityfocus.com/bid/3769 https://exchange.xforce.ibmcloud.com/vulnerabilities/7743 •

CVSS: 5.0EPSS: 2%CPEs: 1EXPL: 1

AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag. • http://www.kb.cert.org/vuls/id/530299 http://www.kb.cert.org/vuls/id/JARL-569MD7 http://www.securityfocus.com/archive/1/218920 http://www.securityfocus.com/archive/1/247707 http://www.securityfocus.com/bid/3756 https://exchange.xforce.ibmcloud.com/vulnerabilities/7757 •

CVSS: 5.0EPSS: 3%CPEs: 11EXPL: 3

AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments. • http://archives.neohapsis.com/archives/bugtraq/2001-10/0014.html http://www.kb.cert.org/vuls/id/507771 http://www.kb.cert.org/vuls/id/JARL-56TPTN http://www.securityfocus.com/archive/1/247707 http://www.securityfocus.com/bid/3398 https://exchange.xforce.ibmcloud.com/vulnerabilities/7233 •