Vulnerabilities > Yahoo > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-07-10 | CVE-2007-3638 | Buffer Errors vulnerability in Yahoo Messenger 8.1 Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005. | 6.0 |
2007-02-09 | CVE-2007-0868 | Denial of Service vulnerability in Yahoo! Messenger Chat Room Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors. | 5.0 |
2007-02-06 | CVE-2007-0768 | HTML Injection vulnerability in Yahoo! Messenger Notification Message Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. network yahoo | 4.3 |
2006-10-27 | CVE-2006-5563 | Remote Buffer Overflow vulnerability in Yahoo Messenger 8.0 Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite. | 5.0 |
2006-06-29 | CVE-2006-3298 | Denial of Service vulnerability in Yahoo! Messenger Message Handling Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll. | 5.0 |
2005-05-16 | CVE-2005-1618 | Remote Denial Of Service vulnerability in Yahoo Messenger 5.5/5.6/6.0 The YMSGR URL handler in Yahoo! Messenger 5.x through 6.0 allows remote attackers to cause a denial of service (disconnect) via a room login or a room join request packet with a third : (colon) and an & (ampersand), which causes Messenger to send a corrupted packet to the server, which triggers a disconnect from the server. | 5.0 |
2005-02-18 | CVE-2005-0242 | Unspecified vulnerability in Yahoo Messenger The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions. | 4.6 |
2005-02-17 | CVE-2005-0243 | Unspecified vulnerability in Yahoo Messenger Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions. | 5.0 |
2002-12-31 | CVE-2002-2361 | Permissions, Privileges, and Access Controls vulnerability in Yahoo Messenger 4.0/5.0/5.5 The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing. | 5.8 |
2002-12-31 | CVE-2002-1664 | Information Disclosure vulnerability in Yahoo Messenger 5.0 Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. | 6.4 |