Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2009-4831

Disclosure Date: April 29, 2010 (last updated October 04, 2023)
Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate.
0
Attacker Value
Unknown

CVE-2008-6563

Disclosure Date: March 31, 2009 (last updated October 04, 2023)
Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DTD file.
0
Attacker Value
Unknown

CVE-2008-5402

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expression, related to the "IMG SRC ID."
0
Attacker Value
Unknown

CVE-2008-5403

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the XML parser in the AIM plugin in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a malformed XML tag.
0
Attacker Value
Unknown

CVE-2008-5401

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."
0
Attacker Value
Unknown

CVE-2008-2409

Disclosure Date: May 23, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.
0
Attacker Value
Unknown

CVE-2008-2008

Disclosure Date: April 29, 2008 (last updated October 04, 2023)
Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.
0
Attacker Value
Unknown

CVE-2007-3833

Disclosure Date: July 17, 2007 (last updated October 04, 2023)
The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.
0
Attacker Value
Unknown

CVE-2007-3832

Disclosure Date: July 17, 2007 (last updated October 04, 2023)
Buffer overflow in the AOL Instant Messenger (AIM) protocol handler in AIM.DLL in Cerulean Studios Trillian allows remote attackers to execute arbitrary code via a malformed aim: URI, as demonstrated by a long URI beginning with the aim:///#1111111/ substring.
0
Attacker Value
Unknown

CVE-2007-2479

Disclosure Date: May 03, 2007 (last updated November 24, 2024)
Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.
0