Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dailyfinance Stocks \& News MEDIUM 5.4
CVE-2014-5570

The DailyFinance - Stocks & News (aka com.aol.mobile.dailyFinance) application 2.0.2.1 for Android does not verify X.509 certificates from SSL server…

Mitigation only
Fix from $1,600 2014-09-09
Aim MEDIUM 5.8
CVE-2012-5816

AOL Instant Messenger (AIM) 1.0.1.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…

No fix yet
Fix from $1,600 2012-11-04
Aolserver MEDIUM 5.0
CVE-2009-4494EPSS 9%

AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,…

No fix yet
Fix from $1,600 2010-01-13
Superbuddy Activex Control HIGH 8.8
CVE-2009-3658EPSS 9%

Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memor…

No fix yet
Fix from $1,950 2009-10-09
Aolmediaplaybackcontrol HIGH 9.3
CVE-2007-6250EPSS 24%

Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow rem…

Mitigation only
Fix from $1,950 2008-01-09
Radio HIGH 9.3
CVE-2007-5755EPSS 13%

Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary c…

Patch available
Fix from $1,950 2007-11-14
Instant Messenger MEDIUM 6.8
CVE-2007-5124

The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.5.3.12 and earlier allows remote attackers to execute arbitrary code v…

Fix: after 6.5.3.12
Fix from $1,600 2007-09-27
Aim Lite MEDIUM 5.8
CVE-2007-4901

The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain…

Mitigation only
Fix from $1,600 2007-09-14
Instant Messenger HIGH 7.8
CVE-2007-3437

AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application crash) via a malformed header va…

Mitigation only
Fix from $1,950 2007-06-27
Instant Messenger HIGH 7.8
CVE-2007-3350

AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP…

Mitigation only
Fix from $1,950 2007-06-22
Aol HIGH 9.3
CVE-2006-5820EPSS 8%

The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function …

Mitigation only
Fix from $1,950 2007-04-02
Aol Client Software HIGH 7.8
CVE-2007-1767

Unspecified vulnerability in (1) Deskbar.dll and (2) Toolbar.dll in AOL 9.0 before February 2007 allows remote attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2007-03-30
Aol Client Software HIGH 9.3
CVE-2006-6442EPSS 5%

Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America …

Mitigation only
Fix from $1,950 2006-12-10
Icq HIGH 7.5
CVE-2006-5650EPSS 67%

The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the Downlo…

Mitigation only
Fix from $1,950 2006-11-07
Aol HIGH 7.5
CVE-2006-5501

Buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition allows remote …

Patch available
Fix from $1,950 2006-10-25
Aol HIGH 7.5
CVE-2006-5502

Heap-based buffer overflow in the AOL.PicDownloadCtrl.1 ActiveX control (YGPPicDownload.dll) 9.2.3.0 in America Online (AOL) 9.0 Security Edition all…

Patch available
Fix from $1,950 2006-10-25
Ygp Screensaver Activex Control HIGH 7.5
CVE-2006-3887

Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecified vector…

Mitigation only
Fix from $1,950 2006-10-10
Ygp Pic Downloader Activex Control HIGH 7.5
CVE-2006-3888EPSS 6%

Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in …

Mitigation only
Fix from $1,950 2006-10-10
Aol HIGH 7.2
CVE-2006-0948

AOL 9.0 Security Edition revision 4184.2340, and probably other versions, uses insecure permissions (Everyone/Full Control) for the "America Online 9…

Patch available
Fix from $1,950 2006-08-21
Instant Messenger MEDIUM 5.1
CVE-2006-0629

Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denial of service (client crash) a…

Mitigation only
Fix from $1,600 2006-02-10
Aol Client Software HIGH 7.2
CVE-2006-0526

The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file n…

Mitigation only
Fix from $1,950 2006-02-02
Aol Client Software HIGH 10.0
CVE-2006-0316EPSS 10%

Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Class…

Patch available
Fix from $1,950 2006-01-19
Aol Client Software HIGH 7.2
CVE-2005-2597

AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privilege…

Mitigation only
Fix from $1,950 2005-08-17
Aim HIGH 7.5
CVE-2005-1891

The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a…

Fix: after 5.9.3797
Fix from $1,950 2005-06-09
Instant Messenger MEDIUM 5.0
CVE-2005-1655

AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in th…

No fix yet
Fix from $1,600 2005-05-18
Instant Messenger MEDIUM 5.0
CVE-2001-1420

AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a bu…

No fix yet
Fix from $1,600 2005-05-02
Instant Messenger HIGH 7.5
CVE-2004-2373

The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a s…

No fix yet
Fix from $1,950 2004-12-31
Instant Messenger HIGH 10.0
CVE-2004-0636EPSS 66%

Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers…

Patch available
Fix from $1,950 2004-11-23
Instant Messenger HIGH 10.0
CVE-2003-1503

Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen n…

Patch available
Fix from $1,950 2003-12-31
Instant Messenger MEDIUM 5.0
CVE-2002-1953

Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,600 2002-12-31