Vulnerabilities > ROB Flynn > Gaim

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0208 Remote Denial of Service vulnerability in Gaim
The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.
network
low complexity
rob-flynn
5.0
2005-03-14 CVE-2005-0473 Remote Denial of Service vulnerability in Gaim
The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.
network
low complexity
rob-flynn mandrakesoft redhat
5.0
2005-03-14 CVE-2005-0472 Remote Denial of Service vulnerability in Gaim
Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.
network
low complexity
rob-flynn mandrakesoft redhat
5.0
2005-01-27 CVE-2004-0891 Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
network
low complexity
rob-flynn gentoo slackware ubuntu
critical
10.0
2004-12-31 CVE-2004-2589 Multiple vulnerability in Gaim
Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length header, which causes Gaim to abort when attempting to allocate memory.
network
low complexity
rob-flynn
5.0
2004-10-20 CVE-2004-0785 Multiple vulnerability in Gaim
Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.
network
low complexity
rob-flynn
7.5
2004-10-20 CVE-2004-0784 Unspecified vulnerability in ROB Flynn Gaim
The smiley theme functionality in Gaim before 0.82 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector.
network
low complexity
rob-flynn
7.5
2004-10-20 CVE-2004-0754 Multiple vulnerability in Gaim
Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.
network
low complexity
rob-flynn
7.5
2004-09-28 CVE-2004-0500 MSN Protocol Buffer Overflow vulnerability in Gaim
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
network
low complexity
rob-flynn gentoo mandrakesoft
7.5
2004-03-03 CVE-2004-0008 Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.
network
low complexity
rob-flynn ultramagnetic
7.5