Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
yahoo vulnerabilities and exploits
(subscribe to this query)
9.3
CVSSv2
CVE-2006-6603
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) prior to 2005.1.1.4 in Yahoo! Messenger allows remote malicious users to execute arbitrary code via a crafted HTML document. NOTE: some details were obtained from third party information.
Yahoo Messenger 5.5
Yahoo Messenger 5.6
Yahoo Messenger 7.5
Yahoo Messenger
Yahoo Messenger 5.0
Yahoo Messenger 6.0
Yahoo Messenger 7.0
4.3
CVSSv2
CVE-2010-4208
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 up to and including 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote malicious users to inject arbitrary web script or HTML via vectors related to uploader/assets/uplo...
Yahoo Yui 2.5.1
Yahoo Yui 2.5.2
Yahoo Yui 2.8.1
Yahoo Yui 2.5.0
Yahoo Yui 2.8.0
Yahoo Yui 2.6.0
Yahoo Yui 2.7.0
9.3
CVSSv2
CVE-2007-3147
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote malicious users to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party ...
Yahoo Messenger 8.1.0.249
Yahoo Messenger 8.0.1
Yahoo Messenger 8.0 2005.1.1.4
Yahoo Messenger 2.0.1.4
Yahoo Messenger 8.0
Yahoo Messenger 8.0.0.863
3 EDB exploits
9.3
CVSSv2
CVE-2007-3148
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote malicious users to execute arbitrary code via a long server property value to the receive method.
Yahoo Messenger 8.0 2005.1.1.4
Yahoo Messenger 8.1.0.249
Yahoo Messenger 2.0.1.4
Yahoo Messenger 8.0
Yahoo Messenger 8.0.0.863
Yahoo Messenger 8.0.1
2 EDB exploits
5
CVSSv2
CVE-2005-0243
Yahoo! Messenger 6.0.0.1750, and possibly other versions prior to 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote malicious users to trick users into downloading and executing programs via file names containing a large number of...
Yahoo Messenger 5.6
Yahoo Messenger 5.6.0.1351
Yahoo Messenger 6.0
Yahoo Messenger 6.0.0.1750
Yahoo Messenger 5.5
4.6
CVSSv2
CVE-2005-0242
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows malicious users to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
Yahoo Messenger 6.0.0.1750
Yahoo Messenger 6.0
Yahoo Messenger 5.5
Yahoo Messenger 5.6
Yahoo Messenger 5.6.0.1351
9.3
CVSSv2
CVE-2007-1680
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger prior to 20070313 allows remote malicious users to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
Yahoo Messenger 8.0 2005.1.1.4
Yahoo Messenger 8.1.0.209
Yahoo Messenger 8.0
Yahoo Messenger 8.0.0.863
Yahoo Messenger 8.1.0.239
2.1
CVSSv2
CVE-2005-1671
The Logfile feature in Yahoo! Messenger 5.x up to and including 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local...
Yahoo Messenger 5.5
Yahoo Messenger 5.6
Yahoo Messenger 5.6.0.1351
Yahoo Messenger 6.0
5.8
CVSSv2
CVE-2002-2361
The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote malicious users to install trojan programs via DNS spoofing.
Yahoo Messenger 4.0
Yahoo Messenger 5.0
Yahoo Messenger 5.5
5
CVSSv2
CVE-2005-1618
The YMSGR URL handler in Yahoo! Messenger 5.x up to and including 6.0 allows remote malicious users to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted...
Yahoo Messenger 5.6
Yahoo Messenger 6.0
Yahoo Messenger 5.5
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »