Vulnerabilities > CVE-2004-0636 - Unspecified vulnerability in AOL Instant Messenger 5.5/5.5.3415Beta/5.5.3595

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
aol
critical
exploit available
metasploit

Summary

Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.

Vulnerable Configurations

Part Description Count
Application
Aol
3

Exploit-Db

  • descriptionAOL Instant Messenger goaway Overflow. CVE-2004-0636. Remote exploit for windows platform
    idEDB-ID:16525
    last seen2016-02-02
    modified2010-07-03
    published2010-07-03
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16525/
    titleAOL Instant Messenger goaway Overflow
  • descriptionAOL Instant Messenger AIM "Away" Message Local Exploit. CVE-2004-0636. Local exploit for windows platform
    idEDB-ID:395
    last seen2016-01-31
    modified2004-08-14
    published2004-08-14
    reportermandragore
    sourcehttps://www.exploit-db.com/download/395/
    titleAOL Instant Messenger AIM "Away" Message Local Exploit
  • descriptionAOL Instant Messenger AIM "Away" Message Remote Exploit. CVE-2004-0636. Remote exploit for windows platform
    idEDB-ID:431
    last seen2016-01-31
    modified2004-09-02
    published2004-09-02
    reporterJohn Bissell
    sourcehttps://www.exploit-db.com/download/431/
    titleAOL Instant Messenger AIM "Away" Message Remote Exploit

Metasploit

descriptionThis module exploits a flaw in the handling of AOL Instant Messenger's 'goaway' URI handler. An attacker can execute arbitrary code by supplying an overly sized buffer as the 'message' parameter. This issue is known to affect AOL Instant Messenger 5.5.
idMSF:EXPLOIT/WINDOWS/BROWSER/AIM_GOAWAY
last seen2020-05-23
modified2017-09-09
published2006-07-31
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/browser/aim_goaway.rb
titleAOL Instant Messenger goaway Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83145/aim_goaway.rb.txt
idPACKETSTORM:83145
last seen2016-12-05
published2009-11-26
reporterskape
sourcehttps://packetstormsecurity.com/files/83145/AOL-Instant-Messenger-goaway-Overflow.html
titleAOL Instant Messenger goaway Overflow

Seebug

  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:13762
    last seen2017-11-19
    modified2004-09-02
    published2004-09-02
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-13762
    titleAOL Instant Messenger AIM ""Away"" Message Remote Exploit
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:62867
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-62867
    titleAOL Instant Messenger AIM "Away" Message Remote Exploit
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:62854
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-62854
    titleAOL Instant Messenger AIM "Away" Message Local Exploit
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:14307
    last seen2017-11-19
    modified2004-08-14
    published2004-08-14
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-14307
    titleAOL Instant Messenger AIM ""Away"" Message Local Exploit
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:9089
    last seen2017-11-19
    modified2008-07-16
    published2008-07-16
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-9089
    titleAOL Instant Messenger AIM "Away" Message Local Exploit