CVE-2002-0785: Buffer Overflow
AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0785?
CVE-2002-0785 is classified as a denial of service vulnerability that can crash AOL Instant Messenger.
How do I fix CVE-2002-0785?
To fix CVE-2002-0785, users should upgrade to the latest version of AOL Instant Messenger that addresses this vulnerability.
What versions of AOL Instant Messenger are affected by CVE-2002-0785?
CVE-2002-0785 affects AOL Instant Messenger versions 4.0 through 4.8.2646.
Can CVE-2002-0785 be exploited remotely?
Yes, CVE-2002-0785 can be exploited remotely by sending a specially crafted 'AddBuddy' link.
What causes the denial of service in CVE-2002-0785?
The denial of service in CVE-2002-0785 is caused by a buffer overflow triggered by a large number of comma-separated values in the ScreenName parameter.