5
CVSSv2

CVE-2005-1655

Published: 18/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

AOL Instant Messenger 5.5.x and previous versions allows remote malicious users to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.

Vulnerable Product Search on Vulmon Subscribe to Product

aol instant messenger 2.0.912

aol instant messenger 2.5.1598

aol instant messenger 3.0.1470

aol instant messenger 4.1

aol instant messenger 4.2

aol instant messenger 4.7

aol instant messenger 4.8.2616

aol instant messenger 5.2.3292

aol instant messenger 5.5.3415_beta

aol instant messenger 2.0.996

aol instant messenger 2.0_n

aol instant messenger 2.1.1236

aol instant messenger 2.5.1366

aol instant messenger 4.3

aol instant messenger 4.3.2229

aol instant messenger 4.4

aol instant messenger 4.5

aol instant messenger 5.9.3702

aol instant messenger 1.2

aol instant messenger 3.0.1415

aol instant messenger 3.0_n

aol instant messenger 4.0

aol instant messenger 4.1.2010

aol instant messenger 4.2.1193

aol instant messenger 4.6

aol instant messenger 4.7.2480

aol instant messenger 5.5

aol instant messenger 5.5.3595

aol instant messenger 3.5.1635

aol instant messenger 3.5.1670

aol instant messenger 3.5.1808

aol instant messenger 3.5.1856

aol instant messenger 4.8.2646

aol instant messenger 4.8.2790

aol instant messenger 5.0.2938

aol instant messenger 5.1.3036

Exploits

source: wwwsecurityfocuscom/bid/13553/info AOL Instant Messenger is reported prone to a remote denial of service vulnerability The issue manifests when the affected client application handles a chat invitation, a file transfer, or a game request that contains 'smiley' HTML code that passes invalid data as the location of the 'smiley' ic ...