MidnightBSD

Advisories for grokster

CVE-2002-0314 MEDIUM

fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
fasttrack kazaa 1.3
grokster grokster 1.3
fasttrack kazaa 1.4
grokster grokster 1.3.3
music_city_networks morpheus 1.3.3
fasttrack kazaa 1.2
music_city_networks morpheus 1.3
fasttrack kazaa 1.3.3
CVE-2002-0315 HIGH

fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
fasttrack kazaa 1.3
grokster grokster 1.3
fasttrack kazaa 1.4
grokster grokster 1.3.3
music_city_networks morpheus 1.3.3
fasttrack kazaa 1.5
fasttrack kazaa 1.2
fasttrack kazaa 1.3.3
music_city_networks morpheus 1.3
CVE-2004-2433 HIGH

Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
altnet altnet_download_manager *
kazaa kazaa_media_desktop 2.6.4
grokster grokster 1.3.3
kazaa kazaa_media_desktop 2.0.2
kazaa kazaa_media_desktop 1.3.1
kazaa kazaa_media_desktop 2.0
kazaa kazaa_media_desktop 1.6.1
grokster grokster 1.3
grokster grokster 2.6
altnet altnet_download_manager 4.0.0.4
kazaa kazaa_media_desktop 1.3
kazaa kazaa_media_desktop 1.3.2
CVE-2007-5217 MEDIUM

Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
grokster grokster 2.6
altnet altnet_download_manager 4.0.0.6
kazaa kazaa_media_desktop 3.2.7