Gaim

Vendor:

First CVE: Jan 9, 2001 · Active for 25 years

26
Total CVEs
More Total CVEs than 95% of tracked products
6.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gaim over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2001
25 years ago
Most Recent CVE
Aug 16, 2005
7,648 days ago

CVE Severity & Scoring

Gaim26 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown26 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown26 (100.0%)
User Interaction
None0 (0.0%)
Unknown26 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown26 (100.0%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.
May 11, 20057.534NOYES
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via
Jan 27, 200510.033NONO
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) c
Mar 3, 20047.527NONO
Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a
Oct 20, 20047.526NONO
Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML t
Jan 9, 200110.025NONO
Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to ca
Mar 3, 20047.522NONO
Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM pa
Mar 3, 20047.522NONO
Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.
Oct 20, 20047.521NONO
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code
Sep 28, 20047.521NONO
Buffer overflow in Jabber plug-in for Gaim client before 0.58 allows remote attackers to execute arbitrary code.
Oct 4, 20027.521NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Gaim

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.3.025.02.2%00
1.2.145.64.7%01
1.2.075.63.7%01
1.1.445.64.7%01
1.1.365.43.9%01
1.1.275.44.4%01
1.1.175.44.4%01
1.1.055.54.4%01
1.0.345.64.7%01
1.0.245.64.7%01
1.0.176.14.9%01
1.0.045.64.7%01
1.056.04.0%00
0.82.146.95.9%01
0.8256.55.0%01
0.8145.64.6%01
0.8045.64.6%01
0.7945.64.6%01
0.7856.55.0%01
0.7745.64.6%01