CVE-2010-10015 describes a stack-based buffer overflow in the Phobos.dll ActiveX control within AOL versions up to 9.5, specifically affecting the Phobos.Playlist COM object's Import() method. This vulnerability, with a CVSS score of 8.4 (HIGH), allows remote code execution if a malicious HTML file is opened locally, as the control is not marked safe for scripting. While a Metasploit module exists, the affected legacy AOL 9.5 software is long discontinued and no longer maintained. Despite high community discussion, there is no indication of active exploitation, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AOL | AOL | >= 0, <= 9.5 (Revision 4337.155)CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.