Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.407
EPSS Ranking 97.2%