7.5
CVSSv2

CVE-2004-2373

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Buddy icon file for AOL Instant Messenger (AIM) 4.3 up to and including 5.5 is created in a predictable location, which may allow remote malicious users to use a shell: URI to exploit other vulnerabilities that involve predictable locations.

Vulnerable Product Search on Vulmon Subscribe to Product

aol instant messenger 4.8.2616

aol instant messenger 4.8.2646

aol instant messenger 4.7

aol instant messenger 4.7.2480

aol instant messenger 5.5

aol instant messenger 5.5.3415_beta

aol instant messenger 4.4

aol instant messenger 4.5

aol instant messenger 4.6

aol instant messenger 5.1.3036

aol instant messenger 5.2.3292

aol instant messenger 4.3

aol instant messenger 4.3.2229

aol instant messenger 4.8.2790

aol instant messenger 5.0.2938

Exploits

source: wwwsecurityfocuscom/bid/9698/info It has been reported that AOL Instant Messenger stores imported Buddy Icons in a predictable location on client systems that may allow an attacker to facilitate further attacks which could eventually lead to execution of arbitrary code This issue has been tested on AOL Instant Messenger versions ...