Kazaa is a peer-to-peer file-sharing application whose vulnerability profile centers on its media-desktop product and recurs through memory-safety issues including buffer-boundary violations and unclassified implementation flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kazaa over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5217MEDIUM Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to exec | Oct 5, 2007 | 6.8 | 50 | NO | YES |
CVE-2002-2306HIGH Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages. | Dec 31, 2002 | 7.8 | 30 | NO | YES |
CVE-2004-2433HIGH Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkst | Dec 31, 2004 | 7.5 | 25 | NO | NO |
CVE-2003-1283HIGH KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute | Dec 31, 2003 | 7.5 | 25 | NO | NO |
CVE-2003-1395HIGH Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server. | Dec 31, 2003 | 9.0 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kazaa.
Media articles that mention a CVE ID that affects a product developed by Kazaa — matched by CVE ID, not by vendor name.