Filtered by vendor Yahoo
Subscribe
Total
66 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-4873 | 1 Yahoo | 1 Tumblr | 2017-08-28 | 5.0 MEDIUM | N/A |
The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2012-5881 | 1 Yahoo | 1 Yui | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207. | |||||
CVE-2012-5883 | 2 Mozilla, Yahoo | 2 Bugzilla, Yui | 2017-08-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore.swf, a similar issue to CVE-2010-4209. | |||||
CVE-2010-4710 | 1 Yahoo | 1 Yui | 2017-08-16 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570. | |||||
CVE-2008-2111 | 1 Yahoo | 1 Yahoo Assistant | 2017-08-07 | 9.3 HIGH | N/A |
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption. | |||||
CVE-2007-6535 | 1 Yahoo | 1 Toolbar | 2017-08-07 | 6.8 MEDIUM | N/A |
Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary code via a long string to the IsTaggedBM method. | |||||
CVE-2007-6228 | 1 Yahoo | 1 Toolbar | 2017-07-28 | 6.8 MEDIUM | N/A |
Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to cause a denial of service (browser crash) via a long argument to the c method. | |||||
CVE-2007-3928 | 1 Yahoo | 1 Messenger | 2017-07-28 | 7.6 HIGH | N/A |
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638. | |||||
CVE-2007-4391 | 1 Yahoo | 1 Messenger | 2017-07-28 | 9.3 HIGH | N/A |
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by sending an "invite to view my webcam" request, and then injecting a DLL into the attacker's peer Yahoo! Messenger application when this request is accepted. | |||||
CVE-2007-4515 | 1 Yahoo | 1 Messenger | 2017-07-28 | 9.3 HIGH | N/A |
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information. | |||||
CVE-2017-2253 | 1 Yahoo | 1 Toolbar | 2017-07-20 | 9.3 HIGH | 7.8 HIGH |
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |||||
CVE-2006-3298 | 1 Yahoo | 1 Messenger | 2017-07-19 | 5.0 MEDIUM | N/A |
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll. | |||||
CVE-2004-0043 | 1 Yahoo | 1 Messenger | 2017-07-10 | 7.5 HIGH | N/A |
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature. | |||||
CVE-2003-1129 | 1 Yahoo | 1 Audio Conferencing Activex Control | 2017-07-10 | 2.6 LOW | N/A |
Buffer overflow in the Yahoo! Audio Conferencing (aka Voice Chat) ActiveX control before 1,0,0,45 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a URL with a long hostname to Yahoo! Messenger or Yahoo! Chat. | |||||
CVE-2012-5882 | 1 Yahoo | 1 Yui | 2017-04-20 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208. | |||||
CVE-2005-1618 | 1 Yahoo | 1 Messenger | 2016-10-17 | 5.0 MEDIUM | N/A |
The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server. | |||||
CVE-2005-1671 | 1 Yahoo | 1 Messenger | 2016-10-17 | 2.1 LOW | N/A |
The Logfile feature in Yahoo! Messenger 5.x through 6.0 can be activated by a YMSGR: URL and writes all output to a single ypager.log file, even when there are multiple users, and does not properly warn later users that the feature has been enabled, which allows local users to obtain sensitive information from other users. | |||||
CVE-2002-1665 | 1 Yahoo | 1 Messenger | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field. | |||||
CVE-2002-1664 | 1 Yahoo | 1 Messenger | 2016-10-17 | 6.4 MEDIUM | N/A |
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. | |||||
CVE-2002-0321 | 1 Yahoo | 1 Messenger | 2016-10-17 | 5.0 MEDIUM | N/A |
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks. |