Записи AOL
60 опубликованных записей вендора aol.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 5 %
- Pre-auth RCE
- 29
- С записью об исправлении
- 1,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-20 Improper Input Validation2
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-310 Cryptographic Issues1
- CWE-404 Improper Resource Shutdown or Release1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
60 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2004-0636Готовый эксплойт | Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote aol · instant messenger | Критическая10,0 | — | 66,0 % | 23 нояб. 2004 г. |
50В плане | CVE-2006-5650Готовый эксплойт | The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via taol · icq | Высокая7,5 | — | 67,1 % | 7 нояб. 2006 г. |
45В плане | CVE-2001-1067Proof of concept | Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP requaol · aol server | Критическая10,0 | — | 16,1 % | 31 авг. 2001 г. |
45В плане | CVE-2002-0005Proof of concept | Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via aol · instant messenger | Критическая10,0 | — | 15,5 % | 31 янв. 2002 г. |
44В плане | CVE-2007-6250Эксплойта нет | Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might aol · aolmediaplaybackcontrol · CWE-119 | Критическая9,3 | — | 24,3 % | 9 янв. 2008 г. |
43В плане | CVE-2006-0316Эксплойта нет | Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and aol · aol client software | Критическая10,0 | — | 10,5 % | 18 янв. 2006 г. |
41В плане | CVE-2007-5755Готовый эксплойт | Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute araol · radio · CWE-119 | Критическая9,3 | — | 13,0 % | 13 нояб. 2007 г. |
41В плане | CVE-2003-1503Эксплойта нет | Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a longaol · instant messenger · CWE-119 | Критическая10,0 | — | 4,6 % | 31 дек. 2003 г. |
40В плане | CVE-2006-5820Proof of concept | The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary aol · aol | Критическая9,3 | — | 8,4 % | 2 апр. 2007 г. |
39Наблюдать | CVE-2006-6442Эксплойта нет | Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used inaol · aol client software · CWE-119 | Критическая9,3 | — | 5,5 % | 10 дек. 2006 г. |
38Наблюдать | CVE-2009-3658Proof of concept | Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigaol · superbuddy activex control · CWE-416 | Высокая8,8 | — | 8,9 % | 9 окт. 2009 г. |
38Наблюдать | CVE-2009-2404Эксплойта нет | Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunmozilla · network security services · CWE-119 | Критическая9,3 | — | 4,2 % | 3 авг. 2009 г. |
32Наблюдать | CVE-2000-1093Proof of concept | Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.aol · instant messenger | Высокая7,5 | — | 8,1 % | 9 янв. 2001 г. |
32Наблюдать | CVE-2006-3888Эксплойта нет | Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), asaol · ygp pic downloader activex control | Высокая7,5 | — | 6,0 % | 10 окт. 2006 г. |
31Наблюдать | CVE-2000-1094Proof of concept | Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" commaaol · aim · CWE-120 | Высокая7,5 | — | 4,7 % | 9 янв. 2001 г. |
31Наблюдать | CVE-2006-3887Эксплойта нет | Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecifiaol · ygp screensaver activex control | Высокая7,5 | — | 4,5 % | 10 окт. 2006 г. |
31Наблюдать | CVE-2002-0362Эксплойта нет | Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp reqaol · instant messenger | Высокая7,5 | — | 3,8 % | 29 мая 2002 г. |
31Наблюдать | CVE-2006-5502Эксплойта нет | Heap-based buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edaol · aol | Высокая7,5 | — | 3,4 % | 25 окт. 2006 г. |
31Наблюдать | CVE-2006-5501Эксплойта нет | Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allowaol · aol | Высокая7,5 | — | 3,4 % | 25 окт. 2006 г. |
31Наблюдать | CVE-2002-0587Эксплойта нет | Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allowsaol · aol server | Высокая7,5 | — | 3,2 % | 18 июн. 2002 г. |
31Наблюдать | CVE-2002-0586Эксплойта нет | Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through aol · aol server | Высокая7,5 | — | 2,9 % | 18 июн. 2002 г. |
31Наблюдать | CVE-2004-2373Proof of concept | The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers taol · instant messenger | Высокая7,5 | — | 2,7 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2005-1891Эксплойта нет | The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (craaol · aim · CWE-191 | Высокая7,5 | — | 2,3 % | 9 июн. 2005 г. |
31Наблюдать | CVE-2001-0314Эксплойта нет | Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute aol · aol server | Высокая7,5 | — | 2,0 % | 2 июн. 2001 г. |
31Наблюдать | CVE-2002-1591Эксплойта нет | AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allaol · instant messenger | Высокая7,5 | — | 1,7 % | 8 апр. 2002 г. |
- CVE-2004-063660На этой неделе
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %aol · instant messenger23 нояб. 2004 г.
- CVE-2006-565050В плане
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via t
ВысокаяCVSS 7,5Готовый эксплойтEPSS 67 %aol · icq7 нояб. 2006 г.
- CVE-2001-106745В плане
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP requ
КритическаяCVSS 10,0Proof of conceptEPSS 16 %aol · aol server31 авг. 2001 г.
- CVE-2002-000545В плане
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via
КритическаяCVSS 10,0Proof of conceptEPSS 16 %aol · instant messenger31 янв. 2002 г.
- CVE-2007-625044В плане
Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might
КритическаяCVSS 9,3Эксплойта нетEPSS 24 %aol · aolmediaplaybackcontrol9 янв. 2008 г.
- CVE-2006-031643В плане
Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %aol · aol client software18 янв. 2006 г.
- CVE-2007-575541В плане
Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute ar
КритическаяCVSS 9,3Готовый эксплойтEPSS 13 %aol · radio13 нояб. 2007 г.
- CVE-2003-150341В плане
Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %aol · instant messenger31 дек. 2003 г.
- CVE-2006-582040В плане
The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary
КритическаяCVSS 9,3Proof of conceptEPSS 8 %aol · aol2 апр. 2007 г.
- CVE-2006-644239Наблюдать
Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %aol · aol client software10 дек. 2006 г.
- CVE-2009-365838Наблюдать
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trig
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %aol · superbuddy activex control9 окт. 2009 г.
- CVE-2009-240438Наблюдать
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thun
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %mozilla · network security services3 авг. 2009 г.
- CVE-2000-109332Наблюдать
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %aol · instant messenger9 янв. 2001 г.
- CVE-2006-388832Наблюдать
Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %aol · ygp pic downloader activex control10 окт. 2006 г.
- CVE-2000-109431Наблюдать
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" comma
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %aol · aim9 янв. 2001 г.
- CVE-2006-388731Наблюдать
Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecifi
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %aol · ygp screensaver activex control10 окт. 2006 г.
- CVE-2002-036231Наблюдать
Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp req
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %aol · instant messenger29 мая 2002 г.
- CVE-2006-550231Наблюдать
Heap-based buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Ed
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %aol · aol25 окт. 2006 г.
- CVE-2006-550131Наблюдать
Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allow
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %aol · aol25 окт. 2006 г.
- CVE-2002-058731Наблюдать
Buffer overflow in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %aol · aol server18 июн. 2002 г.
- CVE-2002-058631Наблюдать
Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %aol · aol server18 июн. 2002 г.
- CVE-2004-237331Наблюдать
The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers t
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %aol · instant messenger31 дек. 2004 г.
- CVE-2005-189131Наблюдать
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (cra
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %aol · aim9 июн. 2005 г.
- CVE-2001-031431Наблюдать
Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %aol · aol server2 июн. 2001 г.
- CVE-2002-159131Наблюдать
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could all
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %aol · instant messenger8 апр. 2002 г.