CVE-2005-1891
7.5 · HIGHOverview
CVE-2005-1891 is a high-severity vulnerability affecting aol aim. It was published on June 9, 2005 and has a CVSS 3.1 base score of 7.5 (HIGH).
This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
Technical Description
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.
Remediation
Check the references section for vendor advisories and patches from aol. Update aim to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| aol | aim | 0 | Affected |
References
Frequently Asked Questions
What is CVE-2005-1891?
CVE-2005-1891 is a high-severity vulnerability affecting aol aim. It was published on June 9, 2005 and has a CVSS 3.1 base score of 7.5 (HIGH).
How severe is CVE-2005-1891?
This vulnerability has a CVSS 3.1 base score of 7.5, rated HIGH. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2005-1891?
Check the references section for vendor advisories and patches from aol. Update aim to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2005-1891?
CyberStrike's AI-powered security agents can automatically detect CVE-2005-1891 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related HIGH CVEs from 2005
View all →Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow
Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain p
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users
FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.p
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PAS
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of servi
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determ
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware,