Vulnerabilities > Microsoft > MSN Messenger > 7.5

DATE CVE VULNERABILITY TITLE RISK
2007-08-31 CVE-2007-2931 Improper Input Validation vulnerability in Microsoft MSN Messenger and Windows Live Messenger
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.
network
microsoft CWE-20
critical
9.3
2006-01-22 CVE-2006-0363 Local Security vulnerability in Microsoft MSN Messenger 7.5
The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the original passwords via a program that calls CryptUnprotectData, as demonstrated by the "MSN Password Recovery.exe" program.
local
low complexity
microsoft
2.1