Cerulean Studios
Cerulean Studios Trillian: vulnerabilidades y CVE
Cerulean Studios Trillian tiene 31 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2012-5824 | Media (5.8) | 1.1% | — | 4 nov 2012 | Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL… |
| CVE-2009-4831 | Media (5.8) | 1.4% | — | 29 abr 2010 | Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attackers to obtain MSN credentials via a man-in-the-middle attack with a spoofed SSL certificate. |
| CVE-2008-5403 | Alta (10) | 7.9% | — | 10 dic 2008 | Heap-based buffer overflow in the XML parser in the AIM plugin in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a malformed XML tag. |
| CVE-2008-5402 | Alta (10) | 7.0% | — | 10 dic 2008 | Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expression, related to the "IMG SRC ID." |
| CVE-2008-5401 | Alta (10) | 7.9% | — | 10 dic 2008 | Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing." |
| CVE-2008-2409 | Alta (9.3) | 6.1% | — | 23 may 2008 | Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message. |
| CVE-2008-2008 | Alta (9.3) | 4.1% | — | 29 abr 2008 | Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an… |
| CVE-2007-3832 | Alta (9.3) | 12% | — | 17 jul 2007 | Buffer overflow in the AOL Instant Messenger (AIM) protocol handler in AIM.DLL in Cerulean Studios Trillian allows remote attackers to execute arbitrary code via a malformed aim: URI, as demonstrated by a long URI… |
| CVE-2007-3833 | Media (5) | 2.6% | — | 17 jul 2007 | The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim:… |
| CVE-2007-3305 | Alta (9.3) | 7.7% | — | 21 jun 2007 | Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execute arbitrary code via a message sent through the MSN protocol, or possibly other protocols, with a crafted UTF-8… |
| CVE-2007-2479 | Media (5.9) | 2.5% | — | 3 may 2007 | Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is… |
| CVE-2006-0543 | Media (5) | 1.2% | — | 4 feb 2006 | Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \'d1, (2) \'d2, (3) \'d3, (4)… |
| CVE-2005-3141 | Media (5) | 1.6% | — | 5 oct 2005 | Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a reverse direct connection from a different client, as demonstrated using LICQ. |
| CVE-2005-0874 | Media (5) | 1.5% | — | 2 may 2005 | Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header. |
| CVE-2005-0875 | Media (5) | 1.1% | — | 2 may 2005 | Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header. |
| CVE-2005-0633 | Alta (7.5) | 5.3% | — | 2 mar 2005 | Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file. |
| CVE-2004-1666 | Alta (7.5) | 9.9% | — | 31 dic 2004 | Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character. |
| CVE-2004-2370 | Alta (7.5) | 3.7% | — | 31 dic 2004 | Stack-based buffer overflow in Trillian 0.71 through 0.74f and Trillian Pro 1.0 through 2.01 allows remote attackers to execute arbitrary code via a Yahoo Messenger packet with a long key name. |
| CVE-2004-2304 | Alta (7.5) | 3.8% | — | 31 dic 2004 | Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based… |
| CVE-2003-0520 | Media (5) | 1.3% | — | 18 ago 2003 | Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified. |
| CVE-2002-1485 | Media (5) | 1.3% | — | 2 abr 2003 | The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C". |
| CVE-2002-1486 | Alta (7.5) | 9.4% | — | 2 abr 2003 | Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2)… |
| CVE-2002-1487 | Media (5) | 14% | — | 2 abr 2003 | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243,… |
| CVE-2002-1488 | Media (5) | 3.0% | — | 2 abr 2003 | The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in. |
| CVE-2002-2162 | Media (4.6) | 0.77% | — | 31 dic 2002 | Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Trillian directory, which allows local users to gain access to other user accounts. |
| CVE-2002-2155 | Alta (7.5) | 2.0% | — | 31 dic 2002 | Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC servers to execute arbitrary code via an invite to a channel with format string specifiers in the… |
| CVE-2002-2156 | Alta (7.5) | 2.0% | — | 31 dic 2002 | Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response. |
| CVE-2002-2173 | Alta (7.5) | 3.1% | — | 31 dic 2002 | Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a long DCC Chat message. |
| CVE-2002-2390 | Alta (10) | 5.7% | — | 31 dic 2002 | Buffer overflow in the IDENT daemon (identd) in Trillian 0.6351, 0.725, 0.73, 0.74 and 1.0 pro allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request. |
| CVE-2002-2366 | Media (6.8) | 2.7% | — | 31 dic 2002 | Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in… |