Yahoo
Yahoo Messenger: vulnerabilities and CVEs
Yahoo Messenger has 33 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs33
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-7216 | High (9.3) | 6.8% | — | Sep 11, 2015 | Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in… |
| CVE-2012-0268 | Medium (5.1) | 1.7% | — | Jan 19, 2012 | Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that… |
| CVE-2009-4171 | Medium (4.3) | 5.1% | — | Dec 2, 2009 | An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling… |
| CVE-2007-5017 | Medium (5) | 2.5% | — | Sep 20, 2007 | Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a… |
| CVE-2007-4635 | Medium (5) | 2.1% | — | Aug 31, 2007 | Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe.… |
| CVE-2007-4515 | High (9.3) | 33% | — | Aug 31, 2007 | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified… |
| CVE-2007-4391 | High (9.3) | 9.3% | — | Aug 17, 2007 | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by… |
| CVE-2007-3928 | High (7.6) | 5.7% | — | Jul 21, 2007 | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638. |
| CVE-2007-3638 | Medium (6) | 2.4% | — | Jul 10, 2007 | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005. NOTE: this information is… |
| CVE-2007-3147 | High (9.3) | 40% | — | Jun 11, 2007 | Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method.… |
| CVE-2007-3148 | High (9.3) | 12% | — | Jun 11, 2007 | Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method. |
| CVE-2007-1680 | High (9.3) | 8.4% | — | Apr 6, 2007 | Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1)… |
| CVE-2007-0868 | Medium (5) | 1.2% | — | Feb 9, 2007 | Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors. NOTE: the provenance of this information… |
| CVE-2007-0768 | Medium (4.3) | 1.8% | — | Feb 6, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a… |
| CVE-2006-6603 | High (9.3) | 6.6% | — | Dec 15, 2006 | Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document. NOTE: some details were… |
| CVE-2006-5563 | Medium (5) | 1.7% | — | Oct 27, 2006 | Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite.… |
| CVE-2006-4975 | Low (2.6) | 1.2% | — | Sep 25, 2006 | Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service. |
| CVE-2006-3298 | Medium (5) | 3.0% | — | Jun 29, 2006 | Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll. |
| CVE-2005-1671 | Low (2.1) | 0.37% | — | May 19, 2005 | The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that… |
| CVE-2005-1618 | Medium (5) | 3.2% | — | May 16, 2005 | The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand),… |
| CVE-2005-0737 | High (7.5) | 4.1% | — | May 2, 2005 | Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode. |
| CVE-2005-0242 | Medium (4.6) | 0.46% | — | Feb 18, 2005 | The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is… |
| CVE-2005-0243 | Medium (5) | 1.0% | — | Feb 17, 2005 | Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing… |
| CVE-2004-0043 | High (7.5) | 3.6% | — | Feb 3, 2004 | Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature. |
| CVE-2003-1135 | Low (2.6) | 4.5% | — | Dec 31, 2003 | Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID. |
| CVE-2002-2361 | Medium (5.8) | 1.2% | — | Dec 31, 2002 | The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing. |
| CVE-2002-1664 | Medium (6.4) | 3.2% | — | Dec 31, 2002 | Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. |
| CVE-2002-1665 | High (7.5) | 4.4% | — | Dec 31, 2002 | Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field. |
| CVE-2002-0031 | Medium (4.6) | 4.9% | — | Jul 26, 2002 | Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6)… |
| CVE-2002-0032 | High (7.5) | 3.9% | — | Jul 26, 2002 | Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI. |