Show filters
55 Total Results
Displaying 1-10 of 55
Sort by:
Attacker Value
Unknown

CVE-2011-0487

Disclosure Date: January 18, 2011 (last updated October 04, 2023)
ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetched through an automatic-update mechanism.
0
Attacker Value
Unknown

CVE-2008-7136

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyById method, different vectors than CVE-2008-7135.
0
Attacker Value
Unknown

CVE-2008-7135

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector than CVE-2008-7136.
0
Attacker Value
Unknown

CVE-2009-1915

Disclosure Date: June 04, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL file containing a long URL parameter, which triggers a crash when browsing a folder that contains this file.
0
Attacker Value
Unknown

CVE-2008-1996

Disclosure Date: April 28, 2008 (last updated October 04, 2023)
licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connections.
0
Attacker Value
Unknown

CVE-2008-1920

Disclosure Date: April 23, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted personal status message.
0
Attacker Value
Unknown

CVE-2008-1120

Disclosure Date: March 03, 2008 (last updated October 04, 2023)
Format string vulnerability in the embedded Internet Explorer component for Mirabilis ICQ 6 build 6043 allows remote servers to execute arbitrary code or cause a denial of service (crash) via unspecified vectors related to HTML code generation.
0
Attacker Value
Unknown

CVE-2007-3713

Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Konst CenterICQ 4.9.11 through 4.21 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might overlap CVE-2007-0160.
0
Attacker Value
Unknown

CVE-2007-1904

Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.
0
Attacker Value
Unknown

CVE-2007-0160

Disclosure Date: January 10, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the LiveJournal support (hooks/ljhook.cc) in CenterICQ 4.9.11 through 4.21.0, when using unofficial LiveJournal servers, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by adding the victim as a friend and using long (1) username and (2) real name strings.
0