← Vulnerability feed

Vulnerability record · CVE-2004-0636 · published 23 November 2004

CVE-2004-0636: AOL Instant Messenger goaway URI handler buffer overflow

Aol · Instant Messenger

The aim:goaway URI handler in AOL Instant Messenger 5.5 (including 5.5.3595) contains a buffer overflow in its goaway function. A remote attacker can trigger it by supplying an overly long Away message, which can lead to arbitrary code execution on the victim's machine. The flaw matters because AIM was widely deployed and the handler is reachable from a URI, so the attack can be delivered without the victim running a separate program.

10.0 CVSS 2.0 High EPSS 66% · top 0.7%
10.0CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated remote code execution with complete impact and a very high EPSS score, but the record lacks KEV listing and confirmed in-the-wild exploitation.

What it is

The aim:goaway URI handler in AOL Instant Messenger 5.5 (including 5.5.3595) contains a buffer overflow in its goaway function. A remote attacker can trigger it by supplying an overly long Away message, which can lead to arbitrary code execution on the victim's machine. The flaw matters because AIM was widely deployed and the handler is reachable from a URI, so the attack can be delivered without the victim running a separate program.

Impact

An attacker who triggers the overflow can execute arbitrary code in the context of the AIM client, giving full control of the affected user's session and data. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.

Attack surface

The flaw is reached through the aim:goaway URI handler, meaning a crafted URI or message containing a long Away message is processed by the AIM client. The CVSS 2.0 vector (AV:N/AC:L/Au:N) indicates network reachability with no authentication required, though the record does not state whether user interaction is needed to open the URI.

Exploitation

The record is not listed in CISA KEV and contains no exploit tags, but EPSS gives a 30-day probability of 0.66019 (99.2nd percentile), indicating a high modeled likelihood of exploitation activity. No public exploit code or in-the-wild confirmation is provided in the record.

What to do

  • Apply the vendor patch referenced in the Secunia and iDefense advisories, or upgrade AIM to a fixed release.
  • If AIM 5.5 cannot be patched, remove or disable the aim:goaway URI handler registration so crafted URIs are not passed to the client.
  • Block or filter aim: URI schemes and suspicious Away-message content at email and web gateways.
  • Retire AIM 5.5 where possible, since the product is long end-of-life and no longer receives security fixes.

Detection

  • Monitor for AIM client crashes or abnormal process termination that could indicate a malformed goaway message.
  • Inspect email and web content for aim:goaway URIs with unusually long Away message parameters.
  • Watch for unexpected child processes or network connections spawned by the AIM client process.
  • Review endpoint logs for AIM 5.5 execution alongside suspicious URI handler invocations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0636 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-1503Aol instant messenger memory buffer overflow vulnerabilityBuffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen n…EPSS 4.6%10.0CVE-2002-0005Aol instant messenger vulnerabilityBuffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long ar…EPSS 16%7.8CVE-2007-3437Aol instant messenger vulnerabilityAOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application crash) via a malformed header va…EPSS 1.6%7.8CVE-2007-3350Aol instant messenger vulnerabilityAOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP…EPSS 1.6%7.5CVE-2004-2373Aol instant messenger vulnerabilityThe Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a s…EPSS 2.7%7.5CVE-2002-0592Aol instant messenger vulnerabilityAOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Con…EPSS 1.6%7.5CVE-2002-0362Aol instant messenger vulnerabilityBuffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and …EPSS 3.8%7.5CVE-2002-1591Aol instant messenger vulnerabilityAOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code f…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2004-0636), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.