4.3
CVSSv2

CVE-2007-6699

Published: 04/02/2008 Updated: 15/11/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote malicious users to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy, and (8) UserAgent property values.

Vulnerable Product Search on Vulmon Subscribe to Product

aol ygp piceditor activex control 9.5.1.8

Exploits

source: wwwsecurityfocuscom/bid/27026/info AOL Picture Editor 'YGPPicEditdll' ActiveX control is prone to multiple vulnerabilities that attackers can exploit to crash the application The issues stem from various buffer-overflow conditions An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious HTML ...