Vulnerabilities
Vulnerable Software
Aol:  >> Instant Messenger  Security Vulnerabilities
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).
CVSS Score
10.0
EPSS Score
0.279
Published
2002-01-31
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.
CVSS Score
5.0
EPSS Score
0.026
Published
2001-10-06
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.
CVSS Score
5.0
EPSS Score
0.014
Published
2001-10-06
AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag.
CVSS Score
5.0
EPSS Score
0.024
Published
2001-10-06
AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.
CVSS Score
5.0
EPSS Score
0.071
Published
2001-10-02
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
CVSS Score
5.1
EPSS Score
0.014
Published
2001-01-18
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.
CVSS Score
7.5
EPSS Score
0.085
Published
2001-01-09
Format string vulnerability in AOL Instant Messenger (AIM) 4.1.2010 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by transferring a file whose name includes format characters.
CVSS Score
5.0
EPSS Score
0.013
Published
2000-12-11
The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.
CVSS Score
5.0
EPSS Score
0.006
Published
2000-05-08
AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.
CVSS Score
5.0
EPSS Score
0.007
Published
2000-03-02


Contact Us

Shodan ® - All rights reserved