Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mirabilis

First CVE: Nov 11, 1998Active for: 28 yearsTotal CVEs: 27
32.2
VTI Score
Medium

Mirabilis developed ICQ, an instant-messaging platform that achieved prominent early adoption across consumer and business desktop environments, though its product line remains focused primarily on the core messaging client and web-facing variants. The vendor's vulnerability disclosures span multiple versions and deployment contexts of ICQ, with a durable signal centered on improper input validation and a pattern of public exploit availability for flaws in the messaging and user-interaction layers. The modest volume of tracked vulnerabilities reflects the vendor's narrower scope compared to broad platform vendors, yet the recurring public-exploit tendency underscores the appeal of messaging protocols and client-side interfaces to security researchers and tool developers. Defenders should track patches to ICQ clients in active use and treat messaging-protocol attack surface as a vector for social engineering and credential compromise; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mirabilis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 11, 1998
27 years ago
Most Recent CVE
Nov 4, 2006
7,202 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2000-0046HIGH
Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.
Jan 10, 20007.531NOYES
CVE-2002-1773HIGH
Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long request.
Dec 31, 20027.530NOYES
CVE-2003-0236HIGH
Integer signedness errors in the POP3 client for Mirabilis ICQ Pro 2003a allow remote attackers to execute arbitrary code via the (1) Subject or (2) Date headers.
May 27, 20037.525NONO
CVE-2002-2329HIGH
ICQ client 2001b, 2002a and 2002b allows remote attackers to cause a denial of service (CPU consumption or crash) via a message with a large number of emoticons.
Dec 31, 20027.825NONO
CVE-2000-1078MEDIUM
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.
Dec 11, 20005.024NOYES
CVE-2003-0769MEDIUM
Cross-site scripting (XSS) vulnerability in the ICQ Web Front guestbook (guestbook.html) allows remote attackers to insert arbitrary web script and HTML via the message field.
Sep 22, 20034.322NOYES
CVE-2006-4662HIGH
Heap-based buffer overflow in the MCRegEx__Search function in AOL ICQ Pro 2003b Build 3916 and earlier allows remote attackers to execute arbitrary code via an inconsistent length
Sep 9, 20067.521NONO
CVE-2002-0028HIGH
Buffer overflow in ICQ before 2001B Beta v5.18 Build #3659 allows remote attackers to execute arbitrary code via a Voice Video & Games request.
Feb 27, 20027.521NONO
CVE-1999-1289HIGH
ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote
Nov 11, 19987.521NONO
CVE-2003-0235HIGH
Format string vulnerability in POP3 client for Mirabilis ICQ Pro 2003a allows remote malicious servers to execute arbitrary code via format strings in the response to a UIDL comman
May 27, 20037.520NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
63%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown27 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown27 (100.0%)
User Interaction
None0 (0.0%)
Unknown27 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown27 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
14.8% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mirabilis.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mirabilis — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mirabilis's Products

View all 1 CNAs →

Top CWEs