7.5

CVE-2004-2373

Exploit

The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations.

Data is provided by the National Vulnerability Database (NVD)
AolInstant Messenger Version4.3
AolInstant Messenger Version4.3.2229
AolInstant Messenger Version4.4
AolInstant Messenger Version4.5
AolInstant Messenger Version4.6
AolInstant Messenger Version4.7
AolInstant Messenger Version4.7.2480
AolInstant Messenger Version4.8.2616
AolInstant Messenger Version4.8.2646
AolInstant Messenger Version4.8.2790
AolInstant Messenger Version5.0.2938
AolInstant Messenger Version5.1.3036
AolInstant Messenger Version5.2.3292
AolInstant Messenger Version5.5
AolInstant Messenger Version5.5.3415_beta
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.06% 0.855
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P