Vulnerabilities > CVE-2008-2111 - Resource Management Errors vulnerability in Yahoo Assistant

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
yahoo
CWE-399
critical
exploit available

Summary

The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.

Vulnerable Configurations

Part Description Count
Application
Yahoo
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionYahoo! Assistant 3.6 'yNotifier.dll' ActiveX Control Memory Corruption Vulnerability. CVE-2008-2111. Dos exploit for windows platform
idEDB-ID:31748
last seen2016-02-03
modified2008-05-06
published2008-05-06
reporterSowhat
sourcehttps://www.exploit-db.com/download/31748/
titleYahoo! Assistant 3.6 - 'yNotifier.dll' ActiveX Control Memory Corruption Vulnerability