Vulnerabilities > Yahoo > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-07-10 CVE-2007-3638 Buffer Errors vulnerability in Yahoo Messenger 8.1
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005.
network
yahoo CWE-119
6.0
2007-02-09 CVE-2007-0868 Denial of Service vulnerability in Yahoo! Messenger Chat Room
Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
yahoo
5.0
2007-02-06 CVE-2007-0768 HTML Injection vulnerability in Yahoo! Messenger Notification Message
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields.
network
yahoo
4.3
2006-10-27 CVE-2006-5563 Remote Buffer Overflow vulnerability in Yahoo Messenger 8.0
Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite.
network
low complexity
yahoo
5.0
2006-06-29 CVE-2006-3298 Denial of Service vulnerability in Yahoo! Messenger Message Handling
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll.
network
low complexity
yahoo
5.0
2005-05-16 CVE-2005-1618 Remote Denial Of Service vulnerability in Yahoo Messenger 5.5/5.6/6.0
The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server.
network
low complexity
yahoo
5.0
2005-02-18 CVE-2005-0242 Unspecified vulnerability in Yahoo Messenger
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
local
low complexity
yahoo
4.6
2005-02-17 CVE-2005-0243 Unspecified vulnerability in Yahoo Messenger
Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.
network
low complexity
yahoo
5.0
2002-12-31 CVE-2002-2361 Permissions, Privileges, and Access Controls vulnerability in Yahoo Messenger 4.0/5.0/5.5
The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.
network
yahoo CWE-264
5.8
2002-12-31 CVE-2002-1664 Information Disclosure vulnerability in Yahoo Messenger 5.0
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information.
network
low complexity
yahoo
6.4