Mirabilis developed ICQ, an instant-messaging platform that achieved prominent early adoption across consumer and business desktop environments, though its product line remains focused primarily on the core messaging client and web-facing variants. The vendor's vulnerability disclosures span multiple versions and deployment contexts of ICQ, with a durable signal centered on improper input validation and a pattern of public exploit availability for flaws in the messaging and user-interaction layers. The modest volume of tracked vulnerabilities reflects the vendor's narrower scope compared to broad platform vendors, yet the recurring public-exploit tendency underscores the appeal of messaging protocols and client-side interfaces to security researchers and tool developers. Defenders should track patches to ICQ clients in active use and treat messaging-protocol attack surface as a vector for social engineering and credential compromise; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mirabilis over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0046HIGH Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message. | Jan 10, 2000 | 7.5 | 31 | NO | YES |
CVE-2002-1773HIGH Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request. | Dec 31, 2002 | 7.5 | 30 | NO | YES |
CVE-2003-0236HIGH Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers. | May 27, 2003 | 7.5 | 25 | NO | NO |
CVE-2002-2329HIGH ICQ client 2001b, 2002a and 2002b allows remote attackers to cause a denial of service (CPU consumption or crash) via a message with a large number of emoticons. | Dec 31, 2002 | 7.8 | 25 | NO | NO |
CVE-2000-1078MEDIUM ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character. | Dec 11, 2000 | 5.0 | 24 | NO | YES |
CVE-2003-0769MEDIUM Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field. | Sep 22, 2003 | 4.3 | 22 | NO | YES |
CVE-2006-4662HIGH Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length | Sep 9, 2006 | 7.5 | 21 | NO | NO |
CVE-2002-0028HIGH Buffer overflow in ICQ before 2001B Beta v5.18 Build #3659 allows remote attackers to execute arbitrary code via a Voice Video & Games request. | Feb 27, 2002 | 7.5 | 21 | NO | NO |
CVE-1999-1289HIGH ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote | Nov 11, 1998 | 7.5 | 21 | NO | NO |
CVE-2003-0235HIGH Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL comman | May 27, 2003 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mirabilis.
Media articles that mention a CVE ID that affects a product developed by Mirabilis — matched by CVE ID, not by vendor name.