Show filters
109 Total Results
Displaying 71-80 of 109
Sort by:
Attacker Value
Unknown

CVE-2009-3170

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a (1) .pls or (2) .m3u playlist file.
0
Attacker Value
Unknown

CVE-2009-1944

Disclosure Date: June 05, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.
0
Attacker Value
Unknown

CVE-2007-4901

Disclosure Date: September 14, 2007 (last updated October 04, 2023)
The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC.
0
Attacker Value
Unknown

CVE-2007-2167

Disclosure Date: April 22, 2007 (last updated October 04, 2023)
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.
0
Attacker Value
Unknown

CVE-2007-2168

Disclosure Date: April 22, 2007 (last updated October 04, 2023)
Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-6511

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).
0
Attacker Value
Unknown

CVE-2005-4693

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Gaim-Encryption 2.38-1 on Debian Linux allows remote attackers to cause a denial of service (crash) via a crafted message from an ICQ buddy, possibly involving the GE_received_key function in keys.c.
0
Attacker Value
Unknown

CVE-2005-2102

Disclosure Date: August 16, 2005 (last updated February 22, 2025)
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.
0
Attacker Value
Unknown

CVE-2005-2103

Disclosure Date: August 16, 2005 (last updated February 22, 2025)
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or %n.
Attacker Value
Unknown

CVE-2005-2370

Disclosure Date: July 26, 2005 (last updated February 22, 2025)
Multiple "memory alignment errors" in libgadu, as used in ekg before 1.6rc2, Gaim before 1.5.0, and other packages, allows remote attackers to cause a denial of service (bus error) on certain architectures such as SPARC via an incoming message.
0