cbcvebase.

Cerulean Studios Trillian vulnerabilities

31 known vulnerabilities affecting cerulean_studios/trillian.

Total CVEs
31
CISA KEV
0
Public exploits
7
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH8MEDIUM15

Vulnerabilities

Page 2 of 2
CVE-2012-5824P4MEDIUMCVSS 5.8v5.1.0.192012-11-04
CVE-2012-5824 [MEDIUM] CVE-2012-5824: Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Co Trillian 5.1.0.19 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, a different vulnerability than CVE-2009-4831.
nvd
CVE-2002-2156P4HIGHCVSS 7.5v0.732002-12-31
CVE-2002-2156 [HIGH] CVE-2002-2156: Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.
nvd
CVE-2007-2479P4MEDIUMCVSS 5.9v3.12007-05-03
CVE-2007-2479 [MEDIUM] CWE-200 CVE-2007-2479: Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.
nvd
CVE-2002-2366P4MEDIUMCVSS 6.8v0.73v0.725+1 more2002-12-31
CVE-2002-2366 [MEDIUM] CWE-119 CVE-2002-2366: Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to caus Buffer overflow in the XML parser of Trillian 0.6351, 0.725 and 0.73 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a skin with a long colors file name in trillian.xml.
nvd
CVE-2005-3141P4MEDIUMCVSS 5.0v3.02005-10-05
CVE-2005-3141 [MEDIUM] CVE-2005-3141: Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a rev Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a reverse direct connection from a different client, as demonstrated using LICQ.
nvd
CVE-2006-0543P4MEDIUMCVSS 5.0v3.1.0.1202006-02-04
CVE-2006-0543 [MEDIUM] CVE-2006-0543: Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \'d1, (2) \'d2, (3) \'d3, (4) \'d4, and (5) \'d5. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2002-1485P4MEDIUMCVSS 5.0v0.73v0.742003-04-02
CVE-2002-1485 [MEDIUM] CVE-2002-1485: The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (cr The AIM component of Trillian 0.73 and 0.74 allows remote attackers to cause a denial of service (crash) via certain strings such as "P > O < C".
nvd
CVE-2005-0874P4MEDIUMCVSS 5.0v2.02005-05-02
CVE-2005-0874 [MEDIUM] CVE-2005-0874: Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allo Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.
nvd
CVE-2005-0875P4MEDIUMCVSS 5.0v2.0v3.0+1 more2005-05-02
CVE-2005-0875 [MEDIUM] CVE-2005-0875: Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web serve Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.
nvd
CVE-2003-0520P4MEDIUMCVSS 5.0v0.74v1.02003-08-18
CVE-2003-0520 [MEDIUM] CVE-2003-0520: Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via Trillian 1.0 Pro and 0.74 Freeware allows remote attackers to cause a denial of service (crash) via a TypingUser message in which the "TypingUser" string has been modified.
nvd
CVE-2001-1419P4MEDIUMCVSS 5.0v0.63512001-10-02
CVE-2001-1419 [MEDIUM] CVE-2001-1419: AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of servic AOL Instant Messenger (AIM) 4.7.2480 and earlier allows remote attackers to cause a denial of service (application crash) via an instant message that contains a large amount of "<!--" HTML comments.
nvd
Cerulean Studios Trillian vulnerabilities | cvebase