AOL records
60 published records for vendor aol.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 5%
- Pre-auth RCE
- 29
- With a fix record
- 1.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-20 Improper Input Validation2
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-310 Cryptographic Issues1
- CWE-404 Improper Resource Shutdown or Release1
The weakness classes this vendor ships most often: where to look.
CWEAll records
60 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2004-0636Weaponized | Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote aol · instant messenger | Critical10.0 | — | 66.0% | Nov 23, 2004 |
50Plan | CVE-2006-5650Weaponized | The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via taol · icq | High7.5 | — | 67.1% | Nov 7, 2006 |
45Plan | CVE-2001-1067Proof of concept | Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP requaol · aol server | Critical10.0 | — | 16.1% | Aug 31, 2001 |
45Plan | CVE-2002-0005Proof of concept | Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via aol · instant messenger | Critical10.0 | — | 15.5% | Jan 31, 2002 |
44Plan | CVE-2007-6250No exploit | Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might aol · aolmediaplaybackcontrol · CWE-119 | Critical9.3 | — | 24.3% | Jan 9, 2008 |
43Plan | CVE-2006-0316No exploit | Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and aol · aol client software | Critical10.0 | — | 10.5% | Jan 18, 2006 |
41Plan | CVE-2007-5755Weaponized | Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute araol · radio · CWE-119 | Critical9.3 | — | 13.0% | Nov 13, 2007 |
41Plan | CVE-2003-1503No exploit | Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a longaol · instant messenger · CWE-119 | Critical10.0 | — | 4.6% | Dec 31, 2003 |
40Plan | CVE-2006-5820Proof of concept | The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary aol · aol | Critical9.3 | — | 8.4% | Apr 2, 2007 |
39Monitor | CVE-2006-6442No exploit | Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used inaol · aol client software · CWE-119 | Critical9.3 | — | 5.5% | Dec 10, 2006 |
38Monitor | CVE-2009-3658Proof of concept | Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigaol · superbuddy activex control · CWE-416 | High8.8 | — | 8.9% | Oct 9, 2009 |
38Monitor | CVE-2009-2404No exploit | Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunmozilla · network security services · CWE-119 | Critical9.3 | — | 4.2% | Aug 3, 2009 |
32Monitor | CVE-2000-1093Proof of concept | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.aol · instant messenger | High7.5 | — | 8.1% | Jan 9, 2001 |
32Monitor | CVE-2006-3888No exploit | Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), asaol · ygp pic downloader activex control | High7.5 | — | 6.0% | Oct 10, 2006 |
31Monitor | CVE-2000-1094Proof of concept | Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" commaaol · aim · CWE-120 | High7.5 | — | 4.7% | Jan 9, 2001 |
31Monitor | CVE-2006-3887No exploit | Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecifiaol · ygp screensaver activex control | High7.5 | — | 4.5% | Oct 10, 2006 |
31Monitor | CVE-2002-0362No exploit | Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp reqaol · instant messenger | High7.5 | — | 3.8% | May 29, 2002 |
31Monitor | CVE-2006-5502No exploit | Heap-based buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edaol · aol | High7.5 | — | 3.4% | Oct 25, 2006 |
31Monitor | CVE-2006-5501No exploit | Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allowaol · aol | High7.5 | — | 3.4% | Oct 25, 2006 |
31Monitor | CVE-2002-0587No exploit | Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allowsaol · aol server | High7.5 | — | 3.2% | Jun 18, 2002 |
31Monitor | CVE-2002-0586No exploit | Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through aol · aol server | High7.5 | — | 2.9% | Jun 18, 2002 |
31Monitor | CVE-2004-2373Proof of concept | The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers taol · instant messenger | High7.5 | — | 2.7% | Dec 31, 2004 |
31Monitor | CVE-2005-1891No exploit | The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (craaol · aim · CWE-191 | High7.5 | — | 2.3% | Jun 9, 2005 |
31Monitor | CVE-2001-0314No exploit | Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute aol · aol server | High7.5 | — | 2.0% | Jun 2, 2001 |
31Monitor | CVE-2002-1591No exploit | AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allaol · instant messenger | High7.5 | — | 1.7% | Apr 8, 2002 |
- CVE-2004-063660This week
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote
CriticalCVSS 10.0WeaponizedEPSS 66%aol · instant messengerNov 23, 2004
- CVE-2006-565050Plan
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via t
HighCVSS 7.5WeaponizedEPSS 67%aol · icqNov 7, 2006
- CVE-2001-106745Plan
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP requ
CriticalCVSS 10.0Proof of conceptEPSS 16%aol · aol serverAug 31, 2001
- CVE-2002-000545Plan
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via
CriticalCVSS 10.0Proof of conceptEPSS 16%aol · instant messengerJan 31, 2002
- CVE-2007-625044Plan
Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might
CriticalCVSS 9.3No exploitEPSS 24%aol · aolmediaplaybackcontrolJan 9, 2008
- CVE-2006-031643Plan
Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and
CriticalCVSS 10.0No exploitEPSS 10%aol · aol client softwareJan 18, 2006
- CVE-2007-575541Plan
Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute ar
CriticalCVSS 9.3WeaponizedEPSS 13%aol · radioNov 13, 2007
- CVE-2003-150341Plan
Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long
CriticalCVSS 10.0No exploitEPSS 5%aol · instant messengerDec 31, 2003
- CVE-2006-582040Plan
The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary
CriticalCVSS 9.3Proof of conceptEPSS 8%aol · aolApr 2, 2007
- CVE-2006-644239Monitor
Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in
CriticalCVSS 9.3No exploitEPSS 5%aol · aol client softwareDec 10, 2006
- CVE-2009-365838Monitor
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trig
HighCVSS 8.8Proof of conceptEPSS 9%aol · superbuddy activex controlOct 9, 2009
- CVE-2009-240438Monitor
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thun
CriticalCVSS 9.3No exploitEPSS 4%mozilla · network security servicesAug 3, 2009
- CVE-2000-109332Monitor
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.
HighCVSS 7.5Proof of conceptEPSS 8%aol · instant messengerJan 9, 2001
- CVE-2006-388832Monitor
Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as
HighCVSS 7.5No exploitEPSS 6%aol · ygp pic downloader activex controlOct 10, 2006
- CVE-2000-109431Monitor
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" comma
HighCVSS 7.5Proof of conceptEPSS 5%aol · aimJan 9, 2001
- CVE-2006-388731Monitor
Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecifi
HighCVSS 7.5No exploitEPSS 4%aol · ygp screensaver activex controlOct 10, 2006
- CVE-2002-036231Monitor
Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp req
HighCVSS 7.5No exploitEPSS 4%aol · instant messengerMay 29, 2002
- CVE-2006-550231Monitor
Heap-based buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Ed
HighCVSS 7.5No exploitEPSS 3%aol · aolOct 25, 2006
- CVE-2006-550131Monitor
Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allow
HighCVSS 7.5No exploitEPSS 3%aol · aolOct 25, 2006
- CVE-2002-058731Monitor
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows
HighCVSS 7.5No exploitEPSS 3%aol · aol serverJun 18, 2002
- CVE-2002-058631Monitor
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through
HighCVSS 7.5No exploitEPSS 3%aol · aol serverJun 18, 2002
- CVE-2004-237331Monitor
The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers t
HighCVSS 7.5Proof of conceptEPSS 3%aol · instant messengerDec 31, 2004
- CVE-2005-189131Monitor
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (cra
HighCVSS 7.5No exploitEPSS 2%aol · aimJun 9, 2005
- CVE-2001-031431Monitor
Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute
HighCVSS 7.5No exploitEPSS 2%aol · aol serverJun 2, 2001
- CVE-2002-159131Monitor
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could all
HighCVSS 7.5No exploitEPSS 2%aol · instant messengerApr 8, 2002