CVE-2007-4034
Estado: ModificadaAlta (9.3)—
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 13%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html
- http://osvdb.org/37705
- http://secunia.com/advisories/26011
- http://www.kb.cert.org/vuls/id/120760
- http://www.securityfocus.com/bid/25086
- http://www.securitytracker.com/id?1018470
- http://www.vupen.com/english/advisories/2007/2679
- http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html
- http://osvdb.org/37705
- http://secunia.com/advisories/26011
- http://www.kb.cert.org/vuls/id/120760
- http://www.securityfocus.com/bid/25086
- http://www.securitytracker.com/id?1018470
- http://www.vupen.com/english/advisories/2007/2679
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4034",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-27T22:30:00.000",
"references": [
{
"url": "http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37705",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26011",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/120760",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25086",
"tags": [
"Exploit",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1018470",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2679",
"source": "cve@mitre.org"
},
{
"url": "http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37705",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26011",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/120760",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25086",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018470",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2679",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "Un desbordamiento de búfer en la región stack de la memoria en el Control ActiveX YDPCTL.YDPControl.1 (también se conoce como Yahoo! Installer Plugin for Widgets) versiones anteriores a 2007.7.13.3 (20070620) en la biblioteca YDPCTL.dll en Yahoo! Widgets versiones anteriores a 4.0.5, permite a atacantes remotos ejecutar código arbitrario por medio de un argumento long en el método GetComponentVersion. NOTA: algunos de estos datos son obtenidos a partir de información de terceros."
}
],
"lastModified": "2026-06-16T22:43:16.733",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:yahoo:widgets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B271EB5-7717-45F1-B1FF-140F2E62747F",
"versionEndIncluding": "4.0.5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}