Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2006-4662
Disclosure Date: September 09, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length field of a Message in a 0x2711 Type-Length-Value (TLV) type.
0
Attacker Value
Unknown
CVE-2006-0766
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.
0
Attacker Value
Unknown
CVE-2006-0765
Disclosure Date: February 18, 2006 (last updated February 22, 2025)
GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs.
0
Attacker Value
Unknown
CVE-2005-3433
Disclosure Date: November 02, 2005 (last updated February 22, 2025)
Buffer overflow in Mirabilis ICQ 2003a allows user-assisted attackers to execute arbitrary code by convincing a user to enter long strings into the First Name and Last Name fields.
0
Attacker Value
Unknown
CVE-2003-0769
Disclosure Date: September 22, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.
0
Attacker Value
Unknown
CVE-2003-0235
Disclosure Date: May 27, 2003 (last updated February 22, 2025)
Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL command.
0
Attacker Value
Unknown
CVE-2003-0238
Disclosure Date: May 27, 2003 (last updated February 22, 2025)
The Message Session window in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service (CPU consumption) by spoofing the address of an ADS server and sending HTML with a -1 width in a table tag.
0
Attacker Value
Unknown
CVE-2003-0237
Disclosure Date: May 27, 2003 (last updated February 22, 2025)
The "ICQ Features on Demand" functionality for Mirabilis ICQ Pro 2003a does not properly verify the authenticity of software upgrades, which allows remote attackers to install arbitrary software via a spoofing attack.
0
Attacker Value
Unknown
CVE-2003-0236
Disclosure Date: May 27, 2003 (last updated February 22, 2025)
Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.
0
Attacker Value
Unknown
CVE-2003-0239
Disclosure Date: May 27, 2003 (last updated February 22, 2025)
icqateimg32.dll parsing/rendering library in Mirabilis ICQ Pro 2003a allows remote attackers to cause a denial of service via malformed GIF89a headers that do not contain a GCT (Global Color Table) or an LCT (Local Color Table) after an Image Descriptor.
0