CVE-2002-0592
Summary
| CVE | CVE-2002-0592 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-06-18 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aol | Instant Messenger | 2.0.912 | All | All | All |
| Application | Aol | Instant Messenger | 2.0.996 | All | All | All |
| Application | Aol | Instant Messenger | 2.0_n | All | All | All |
| Application | Aol | Instant Messenger | 2.1.1236 | All | All | All |
| Application | Aol | Instant Messenger | 2.5.1366 | All | All | All |
| Application | Aol | Instant Messenger | 2.5.1598 | All | All | All |
| Application | Aol | Instant Messenger | 3.0.1415 | All | All | All |
| Application | Aol | Instant Messenger | 3.0.1470 | All | All | All |
| Application | Aol | Instant Messenger | 3.0_n | All | All | All |
| Application | Aol | Instant Messenger | 3.5.1635 | All | All | All |
| Application | Aol | Instant Messenger | 3.5.1670 | All | All | All |
| Application | Aol | Instant Messenger | 3.5.1808 | All | All | All |
| Application | Aol | Instant Messenger | 3.5.1856 | All | All | All |
| Application | Aol | Instant Messenger | 4.0 | All | All | All |
| Application | Aol | Instant Messenger | 4.1 | All | All | All |
| Application | Aol | Instant Messenger | 4.1.2010 | All | All | All |
| Application | Aol | Instant Messenger | 4.2 | All | All | All |
| Application | Aol | Instant Messenger | 4.2.1193 | All | All | All |
| Application | Aol | Instant Messenger | 4.3 | All | All | All |
| Application | Aol | Instant Messenger | 4.3.2229 | All | All | All |
| Application | Aol | Instant Messenger | 4.4 | All | All | All |
| Application | Aol | Instant Messenger | 4.5 | All | All | All |
| Application | Aol | Instant Messenger | 4.6 | All | All | All |
| Application | Aol | Instant Messenger | 4.7 | All | All | All |
| Application | Aol | Instant Messenger | 4.7.2480 | All | All | All |
| Application | Aol | Instant Messenger | 4.8.2616 | All | All | All |
| Application | Aol | Instant Messenger | 4.8.2646 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| AOL Instant Messenger Data Interception Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.