CVE-2002-1953
Published Dec 31, 2002
Last updated 16 years ago
Overview
- Description
- Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:aol:instant_messenger:4.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B2D8157E-3447-44BF-AC22-5A65F4C707E7" }, { "criteria": "cpe:2.3:a:aol:instant_messenger:4.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDA52A0F-2A09-4FA8-AC10-2D1B6B41D13C" }, { "criteria": "cpe:2.3:a:aol:instant_messenger:4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C4FA9B9-E98C-435C-9F7A-D62E348D92D9" }, { "criteria": "cpe:2.3:a:aol:instant_messenger:4.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0ADB0D5-BD25-488D-87D3-426ABB036B7A" }, { "criteria": "cpe:2.3:a:aol:instant_messenger:4.7.2480:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11FCCE0C-E6F9-4A01-872E-38C5F23C479E" }, { "criteria": "cpe:2.3:a:aol:instant_messenger:4.8.2616:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E80E2514-9F43-48FB-B55E-094F45088D7C" }, { "criteria": "cpe:2.3:a:aol:instant_messenger:4.8.2646:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E553111-8B78-4B66-95BC-FD0EE897DDC4" } ], "operator": "OR" } ] } ]