Yahoo / Messenger
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-7216 | Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execu… | HIGH | 9.3 | Sep 11, 2015 |
| CVE-2012-0268 | Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attacker… | MEDIUM | 5.1 | Jan 19, 2012 |
| CVE-2009-4171 | An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service… | MEDIUM | 4.3 | Dec 2, 2009 |
| CVE-2002-2361 | The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spo… | MEDIUM | 5.8 | Oct 29, 2007 |
| CVE-2007-5017 | Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to forc… | MEDIUM | 5.0 | Sep 20, 2007 |
| CVE-2007-4635 | Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly i… | MEDIUM | 5.0 | Aug 31, 2007 |
| CVE-2007-4515 | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remot… | HIGH | 9.3 | Aug 31, 2007 |
| CVE-2007-4391 | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a… | HIGH | 9.3 | Aug 17, 2007 |
| CVE-2007-3928 | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book… | HIGH | 7.6 | Jul 21, 2007 |
| CVE-2007-3638 | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspe… | MEDIUM | 6.0 | Jul 10, 2007 |
| CVE-2007-3148 | Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary c… | HIGH | 9.3 | Jun 11, 2007 |
| CVE-2007-3147 | Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary c… | HIGH | 9.3 | Jun 11, 2007 |
| CVE-2007-1680 | Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows r… | HIGH | 9.3 | Apr 6, 2007 |
| CVE-2007-0868 | Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via uns… | MEDIUM | 5.0 | Feb 9, 2007 |
| CVE-2007-0768 | Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote a… | MEDIUM | 4.3 | Feb 6, 2007 |
| CVE-2006-6603 | Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code… | HIGH | 9.3 | Dec 15, 2006 |
| CVE-2006-5563 | Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and applicat… | MEDIUM | 5.0 | Oct 27, 2006 |
| CVE-2006-4975 | Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML vi… | LOW | 2.6 | Sep 25, 2006 |
| CVE-2006-3298 | Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which trigg… | MEDIUM | 5.0 | Jun 29, 2006 |
| CVE-2002-1665 | Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a… | HIGH | 7.5 | May 28, 2005 |
| CVE-2002-1664 | Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. | MEDIUM | 6.4 | May 28, 2005 |
| CVE-2005-1671 | The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are… | LOW | 2.1 | May 19, 2005 |
| CVE-2005-1618 | The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join req… | MEDIUM | 5.0 | May 16, 2005 |
| CVE-2003-1135 | Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of… | LOW | 2.6 | May 10, 2005 |
| CVE-2005-0737 | Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode. | HIGH | 7.5 | Mar 13, 2005 |
Showing 1 to 25 of 33 CVEs