The Secure Channel (SChannel) library on Microsoft Windows XP SP1 and SP2 is vulnerable to an off-by-one heap buffer overwrite.
5f7f7dba629f7d54a7c7eeda6d1ca3a68d6aebd6f272d171155cfe734439ff6f
The webmail portion of Infinite Mobile Delivery 2.6 from Captaris, Inc. contains a Cross Site Scripting vulnerability. In addition to the XSS, an even smaller issue exists where a user can determine the installation path of the client and where e-mails are stored.
ab16cccb8d5dac3bb83fa685da0c66ecaf107bea553a5bde32efb50a81721cbf
AOL's Online Password Reset feature does not fully validate user information.
6360be8f77cfa54486b56369d74757273b26fcc9ba88fe0e49590994497345d4
Versions prior to 1.4.2.1 of the ArGoSoft FTP server will disclose whether or not a supplied username is valid or not. A login name supplied with the USER command will not be accepted unless it is valid.
89ccfd2a196725b8e9084c125c42f0d20b43c9aa550dedd42679aa8a4121ac54
An information disclosure flaw in AOL Journals allows any remote attacker to increment BlogIDs in order to reveal other user email addresses.
02d5f5dd347c2ac7772bcb3d661d9a6de4bf662b8460563f0fcc4e1d311b4c14
Netscape.net Webmail is susceptible to a cross site scripting attack.
9b1f9e465e7432d50eb6a8447f25d19cc5a5eca1095f5f58d2e8c658a7225e7c
AOL Webmail suffers from cross site scripting flaws.
aa11806659a7b31d1900f61f5ac6a0d36b32706fdcc06cc4aae18348d7972568