Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown
CVE-2006-5650
Disclosure Date: November 07, 2006 (last updated October 04, 2023)
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
0
Attacker Value
Unknown
CVE-2006-5724
Disclosure Date: November 04, 2006 (last updated October 04, 2023)
Heap-based buffer overflow the "Answering Service" function in ICQ 2003b Build 3916 allows local users to cause a denial of service (application crash) via a long string in the "AwayMsg Presets" value in the ICQ\ICQPro\DefaultPrefs\Presets registry key.
0
Attacker Value
Unknown
CVE-2006-4660
Disclosure Date: September 09, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed module in AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) allow remote attackers to process arbitrary web script or HTML in the Feeds interface context via the (1) title and (2) description elements within an item element in an RSS feed.
0
Attacker Value
Unknown
CVE-2006-4661
Disclosure Date: September 09, 2006 (last updated October 04, 2023)
AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick the user into reconfiguring the toolbar.
0
Attacker Value
Unknown
CVE-2006-4662
Disclosure Date: September 09, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message in a 0x2711 Type-Length-Value (TLV) type.
0
Attacker Value
Unknown
CVE-2006-2303
Disclosure Date: May 11, 2006 (last updated October 04, 2023)
Cross-Application Scripting (XAS) vulnerability in ICQ Client 5.04 build 2321 and earlier allows remote attackers to inject arbitrary web script from one application into another via a banner, which is processed in the My Computer zone using the Internet Explorer COM object.
0
Attacker Value
Unknown
CVE-2006-0766
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.
0
Attacker Value
Unknown
CVE-2006-0765
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs.
0
Attacker Value
Unknown
CVE-2005-3694
Disclosure Date: November 20, 2005 (last updated February 22, 2025)
centericq 4.20.0-r3 with "Enable peer-to-peer communications" set allows remote attackers to cause a denial of service (segmentation fault and crash) via short zero-length packets, and possibly packets of length 1 or 2, as demonstrated using Nessus.
0
Attacker Value
Unknown
CVE-2005-3433
Disclosure Date: November 02, 2005 (last updated February 22, 2025)
Buffer overflow in Mirabilis ICQ 2003a allows user-assisted attackers to execute arbitrary code by convincing a user to enter long strings into the First Name and Last Name fields.
0