Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2008-5402
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expression, related to the "IMG SRC ID."
0
Attacker Value
Unknown
CVE-2008-5403
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the XML parser in the AIM plugin in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a malformed XML tag.
0
Attacker Value
Unknown
CVE-2008-5401
Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."
0
Attacker Value
Unknown
CVE-2008-2409
Disclosure Date: May 23, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.
0
Attacker Value
Unknown
CVE-2002-2162
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts.
0
Attacker Value
Unknown
CVE-2002-2366
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in trillian.xml.
0
Attacker Value
Unknown
CVE-2001-1419
Disclosure Date: October 02, 2001 (last updated February 22, 2025)
AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.
0