9.3
CVSSv2

CVE-2014-7216

Published: 11/09/2015 Updated: 09/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 829
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and previous versions allow remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yahoo messenger

Recent Articles

Yahoo! won't! fix! emoticon! exploit! in! death! row! Messenger!
The Register • Darren Pauli • 10 Sep 2015

Mitre, Purple Palace; Where is the dumb-user line? ¯\_(ツ)_/¯

Updated Hacker Julien Ahrens says Yahoo! Messenger contains a remote code execution hole that the Purple Palace won't fix. The buffer overflow holes (CVE-2014-7216) will keep bleeding, Ahrens says, because Yahoo! has told him the relevant app is end-of-life and therefore low on Yahoo!'s to-do list. Yahoo! has been contacted for comment. Exploiting the flaw relies on victims installing new emoticon packages, a vector Ahrens feels is a very live threat given instant messaging users are rather keen...