VulnerabilityModified
CVE-2001-1416
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY…
MEDIUM 5.1EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messenger (AIM) 4.4 allow remote attackers to execute arbitrary web script or HTML via an image in the (1) DATA, (2) STYLE, or (3) BINARY tags.
- CVSS 2.0
- 5.1 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- aol/instant messenger
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/541384US Government Resource
- http://www.kb.cert.org/vuls/id/JARL-56TPBQUS Government Resource
- http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&DisplayTab=Article
- http://www.kb.cert.org/vuls/id/541384US Government Resource
- http://www.kb.cert.org/vuls/id/JARL-56TPBQUS Government Resource
- http://www.windowsitpro.com/Articles/Index.cfm?ArticleID=19811&DisplayTab=Article
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.