4.3
CVSSv2

CVE-2009-1915

Published: 04/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote malicious users to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL file containing a long URL parameter, which triggers a crash when browsing a folder that contains this file.

Vulnerable Product Search on Vulmon Subscribe to Product

icq icq 6.5

Exploits

<?php /* ICQ 65 URL Search Hook/ICQToolBardll URL file processing Windows Explorer remote buffer overflow poc by Nine:Situations:Group::pyrokinesis site: retrogodaltervistaorg/ If the resulting file is placed on the desktop, against ex xp sp3 process explorerexe will exit with code 1282 (0x502) that is ERROR_STACK_BUFFER_OVERRUN a ...