7.5
CVSSv2

CVE-2008-1920

Published: 23/04/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via a crafted personal status message.

Vulnerable Product Search on Vulmon Subscribe to Product

icq mirabilis icq 6.0

Exploits

source: wwwsecurityfocuscom/bid/28803/info ICQ is prone to a remote buffer-overflow vulnerability because the application fails to perform boundary checks before copying user-supplied data into sensitive process buffers A remote attacker may execute arbitrary code in the context of the affected application Failed exploit attempts will ...