Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2012-5824
Disclosure Date: November 04, 2012 (last updated October 05, 2023)
Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than CVE-2009-4831.
0
Attacker Value
Unknown
CVE-2009-4831
Disclosure Date: April 29, 2010 (last updated October 04, 2023)
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.
0
Attacker Value
Unknown
CVE-2008-6563
Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DTD file.
0
Attacker Value
Unknown
CVE-2008-5402
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expression, related to the "IMG SRC ID."
0
Attacker Value
Unknown
CVE-2008-5403
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the XML parser in the AIM plugin in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a malformed XML tag.
0
Attacker Value
Unknown
CVE-2008-5401
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."
0
Attacker Value
Unknown
CVE-2008-2408
Disclosure Date: May 23, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the XML parsing functionality in talk.dll in Cerulean Studios Trillian Pro before 3.1.10.0 allows remote attackers to execute arbitrary code via a malformed attribute in an IMG tag.
0
Attacker Value
Unknown
CVE-2008-2407
Disclosure Date: May 23, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in AIM.DLL in Cerulean Studios Trillian before 3.1.10.0 allows user-assisted remote attackers to execute arbitrary code via a long attribute value in a FONT tag in a message.
0
Attacker Value
Unknown
CVE-2008-2409
Disclosure Date: May 23, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.
0
Attacker Value
Unknown
CVE-2008-2008
Disclosure Date: April 29, 2008 (last updated October 04, 2023)
Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.
0