Vulnerabilities > AOL

DATE CVE VULNERABILITY TITLE RISK
2002-03-25 CVE-2002-0100 Unspecified vulnerability in AOL Server 3.4.2
AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file.
network
low complexity
aol
7.5
2002-01-31 CVE-2002-0005 Remote Buffer Overflow in AOL Instant Messenger
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).
network
low complexity
aol
critical
10.0
2001-10-06 CVE-2001-1421 Denial of Service vulnerability in AOL Instant Messenger Font
AOL Instant Messenger (AIM) 4.7 and earlier allows remote attackers to cause a denial of service (application crash) via a large number of different fonts followed by an HTML HR tag.
network
low complexity
aol
5.0
2001-10-06 CVE-2001-1418 Denial-Of-Service vulnerability in AOL Instant Messenger 4.7
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.
network
low complexity
aol
5.0
2001-10-06 CVE-2001-1417 Denial of Service vulnerability in AOL Instant Messenger 4.7
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application hang or crash) via a buddy icon GIF file whose length and width values are larger than the actual image data.
network
low complexity
aol
5.0
2001-10-02 CVE-2001-1419 AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.
network
low complexity
aol cerulean-studios
5.0
2001-08-31 CVE-2001-1067 Buffer Overflow vulnerability in AOLServer Long Authentication String
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.
network
low complexity
aol
critical
10.0
2001-06-02 CVE-2001-0314 Denial-Of-Service vulnerability in AOL Server 5.0
Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.
network
low complexity
aol
7.5
2001-05-03 CVE-2001-0205 Directory Traversal vulnerability in AOL Server 3.2
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified ..
network
low complexity
aol
5.0
2001-01-18 CVE-2001-1416 Unspecified vulnerability in AOL Instant Messenger 4.4A
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
network
high complexity
aol
5.1