Описание
AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- US Government Resource
- Vendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
- US Government Resource
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:aol:instant_messenger:4.0:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.1:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.1.2010:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.2:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.2.1193:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.3:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.3.2229:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.4:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.5:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.6:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.7:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.7.2480:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.8.2616:*:*:*:*:*:*:*
cpe:2.3:a:aol:instant_messenger:4.8.2646:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02238
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.
EPSS
Процентиль: 84%
0.02238
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other