ICQ Inc's vulnerability footprint centers on a narrowly scoped portfolio of legacy instant-messaging and browser toolbar products, including ICQ Lite and ICQ Toolbar. The observed disclosures reflect the application-integration and data-handling characteristics typical of early-2000s communication and browser-extension software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icq Inc over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1920HIGH Heap-based buffer overflow in the boxelyRenderer module in the Personal Status Manager feature in ICQ 6.0 build 6043 allows remote attackers to cause a denial of service (crash) or | Apr 23, 2008 | 7.5 | 30 | NO | YES |
CVE-2011-0487HIGH ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetched through an automatic-update | Jan 18, 2011 | 9.3 | 26 | NO | NO |
CVE-2008-1120HIGH Format string vulnerability in the embedded Internet Explorer component for Mirabilis ICQ 6 build 6043 allows remote servers to execute arbitrary code or cause a denial of service | Mar 3, 2008 | 9.3 | 24 | NO | NO |
CVE-2000-0552MEDIUM ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information. | Jun 6, 2000 | 5.5 | 23 | NO | YES |
CVE-2008-7136MEDIUM toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or | Sep 1, 2009 | 4.3 | 22 | NO | YES |
CVE-2009-1915MEDIUM Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrar | Jun 4, 2009 | 4.3 | 22 | NO | YES |
CVE-2008-7135MEDIUM toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the IsChecked method, a different vector th | Sep 1, 2009 | 4.3 | 21 | NO | YES |
CVE-2006-4660MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed module in AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) allow remote attackers to process arbitrary w | Sep 9, 2006 | 5.8 | 16 | NO | NO |
CVE-1999-1342MEDIUM ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port. | Oct 17, 1999 | 5.0 | 15 | NO | NO |
CVE-2003-0365MEDIUM ICQLite 2003a creates the ICQ Lite directory with an ACE for "Full Control" privileges for Interactive Users, which allows local users to gain privileges as other users by replacin | Jun 16, 2003 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icq Inc.
Media articles that mention a CVE ID that affects a product developed by Icq Inc — matched by CVE ID, not by vendor name.