VYPR

AOL Desktop

by AOL

CVEs (2)

  • CVE-2010-10015HigAug 21, 2025
    risk 0.58cvss epss 0.01

    AOL versions up to and including 9.5 includes an ActiveX control (Phobos.dll) that exposes a method called Import() via the Phobos.Playlist COM object. This method is vulnerable to a stack-based buffer overflow when provided with an excessively long string argument. Exploitation…

  • CVE-2011-10027HigAug 20, 2025
    risk 0.58cvss epss 0.01

    AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of unsafe strcpy operations. This allows…