VYPR

by AOL

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2006-56500.100.84Nov 7, 2006The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.
CVE-2007-19040.000.01Apr 10, 2007Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.