Записи yahoo
67 опубликованных записей вендора yahoo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 3 %
- Pre-auth RCE
- 20
- С записью об исправлении
- 9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-310 Cryptographic Issues3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation2
- CWE-255 Credentials Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
67 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2007-3147Готовый эксплойт | Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to yahoo · messenger · CWE-119 | Критическая9,3 | — | 40,4 % | 11 июн. 2007 г. |
47В плане | CVE-2007-4515Готовый эксплойт | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1yahoo · messenger · CWE-119 | Критическая9,3 | — | 33,0 % | 31 авг. 2007 г. |
41В плане | CVE-2007-4034Proof of concept | Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (2007062yahoo · widgets · CWE-119 | Критическая9,3 | — | 13,0 % | 27 июл. 2007 г. |
41В плане | CVE-2007-3148Proof of concept | Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to yahoo · messenger · CWE-119 | Критическая9,3 | — | 12,3 % | 11 июн. 2007 г. |
40В плане | CVE-2007-4391Proof of concept | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (applicyahoo · messenger · CWE-20 | Критическая9,3 | — | 9,3 % | 17 авг. 2007 г. |
40В плане | CVE-2007-1680Эксплойта нет | Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger beforyahoo · messenger | Критическая9,3 | — | 8,4 % | 5 апр. 2007 г. |
39Наблюдать | CVE-2014-7216Эксплойта нет | Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash)yahoo · messenger · CWE-119 | Критическая9,3 | — | 6,8 % | 11 сент. 2015 г. |
39Наблюдать | CVE-2006-6603Эксплойта нет | Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execyahoo · messenger | Критическая9,3 | — | 6,6 % | 15 дек. 2006 г. |
39Наблюдать | CVE-2008-2111Proof of concept | The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified veyahoo · yahoo assistant · CWE-399 | Критическая9,3 | — | 5,4 % | 7 мая 2008 г. |
32Наблюдать | CVE-2002-0320Эксплойта нет | Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long yahoo · messenger | Высокая7,5 | — | 7,0 % | 25 июн. 2002 г. |
32Наблюдать | CVE-2007-3928Эксплойта нет | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address yahoo · messenger · CWE-119 | Высокая7,6 | — | 5,7 % | 20 июл. 2007 г. |
31Наблюдать | CVE-2002-1665Эксплойта нет | Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute ayahoo · messenger | Высокая7,5 | — | 4,4 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2005-0737Proof of concept | Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.yahoo · messenger | Высокая7,5 | — | 4,1 % | 2 мая 2005 г. |
31Наблюдать | CVE-2002-0032Эксплойта нет | Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymyahoo · messenger | Высокая7,5 | — | 3,9 % | 26 июл. 2002 г. |
31Наблюдать | CVE-2004-0043Эксплойта нет | Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly yahoo · messenger | Высокая7,5 | — | 3,6 % | 3 февр. 2004 г. |
31Наблюдать | CVE-2017-2253Эксплойта нет | Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior toyahoo · toolbar · CWE-426 | Высокая7,8 | — | 1,1 % | 17 июл. 2017 г. |
30Наблюдать | CVE-2002-0322Эксплойта нет | Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.yahoo · messenger | Высокая7,5 | — | 1,6 % | 25 июн. 2002 г. |
30Наблюдать | CVE-2026-34043Эксплойта нет | Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objectsyahoo · serialize · CWE-400 | Высокая7,5 | — | 0,6 % | 30 мар. 2026 г. |
28Наблюдать | CVE-2007-6228Proof of concept | Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to causyahoo · toolbar · CWE-119 | Средняя6,8 | — | 2,1 % | 4 дек. 2007 г. |
28Наблюдать | CVE-2007-6535Эксплойта нет | Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary cyahoo · toolbar · CWE-119 | Средняя6,8 | — | 1,9 % | 27 дек. 2007 г. |
26Наблюдать | CVE-2002-1664Эксплойта нет | Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensityahoo · messenger | Средняя6,4 | — | 3,2 % | 31 дек. 2002 г. |
25Наблюдать | CVE-2007-3638Proof of concept | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbityahoo · messenger · CWE-119 | Средняя6,0 | — | 2,4 % | 9 июл. 2007 г. |
24Наблюдать | CVE-2019-6035Эксплойта нет | Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishyahoo · athenz · CWE-601 | Средняя6,1 | — | 1,1 % | 26 дек. 2019 г. |
23Наблюдать | CVE-2013-2316Эксплойта нет | The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL disyahoo · yahoo\! browser | Средняя5,8 | — | 1,5 % | 3 июн. 2013 г. |
23Наблюдать | CVE-2013-2307Эксплойта нет | The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.yahoo · yahoo\! browser | Средняя5,8 | — | 1,5 % | 26 апр. 2013 г. |
- CVE-2007-314749В плане
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to
КритическаяCVSS 9,3Готовый эксплойтEPSS 40 %yahoo · messenger11 июн. 2007 г.
- CVE-2007-451547В плане
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1
КритическаяCVSS 9,3Готовый эксплойтEPSS 33 %yahoo · messenger31 авг. 2007 г.
- CVE-2007-403441В плане
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (2007062
КритическаяCVSS 9,3Proof of conceptEPSS 13 %yahoo · widgets27 июл. 2007 г.
- CVE-2007-314841В плане
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to
КритическаяCVSS 9,3Proof of conceptEPSS 12 %yahoo · messenger11 июн. 2007 г.
- CVE-2007-439140В плане
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (applic
КритическаяCVSS 9,3Proof of conceptEPSS 9 %yahoo · messenger17 авг. 2007 г.
- CVE-2007-168040В плане
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger befor
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %yahoo · messenger5 апр. 2007 г.
- CVE-2014-721639Наблюдать
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash)
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %yahoo · messenger11 сент. 2015 г.
- CVE-2006-660339Наблюдать
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to exec
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %yahoo · messenger15 дек. 2006 г.
- CVE-2008-211139Наблюдать
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified ve
КритическаяCVSS 9,3Proof of conceptEPSS 5 %yahoo · yahoo assistant7 мая 2008 г.
- CVE-2002-032032Наблюдать
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %yahoo · messenger25 июн. 2002 г.
- CVE-2007-392832Наблюдать
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address
ВысокаяCVSS 7,6Эксплойта нетEPSS 6 %yahoo · messenger20 июл. 2007 г.
- CVE-2002-166531Наблюдать
Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %yahoo · messenger31 дек. 2002 г.
- CVE-2005-073731Наблюдать
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %yahoo · messenger2 мая 2005 г.
- CVE-2002-003231Наблюдать
Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ym
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %yahoo · messenger26 июл. 2002 г.
- CVE-2004-004331Наблюдать
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %yahoo · messenger3 февр. 2004 г.
- CVE-2017-225331Наблюдать
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %yahoo · toolbar17 июл. 2017 г.
- CVE-2002-032230Наблюдать
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %yahoo · messenger25 июн. 2002 г.
- CVE-2026-3404330Наблюдать
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %yahoo · serialize30 мар. 2026 г.
- CVE-2007-622828Наблюдать
Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to caus
СредняяCVSS 6,8Proof of conceptEPSS 2 %yahoo · toolbar4 дек. 2007 г.
- CVE-2007-653528Наблюдать
Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary c
СредняяCVSS 6,8Эксплойта нетEPSS 2 %yahoo · toolbar27 дек. 2007 г.
- CVE-2002-166426Наблюдать
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensit
СредняяCVSS 6,4Эксплойта нетEPSS 3 %yahoo · messenger31 дек. 2002 г.
- CVE-2007-363825Наблюдать
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbit
СредняяCVSS 6,0Proof of conceptEPSS 2 %yahoo · messenger9 июл. 2007 г.
- CVE-2019-603524Наблюдать
Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phish
СредняяCVSS 6,1Эксплойта нетEPSS 1 %yahoo · athenz26 дек. 2019 г.
- CVE-2013-231623Наблюдать
The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL dis
СредняяCVSS 5,8Эксплойта нетEPSS 2 %yahoo · yahoo\! browser3 июн. 2013 г.
- CVE-2013-230723Наблюдать
The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.
СредняяCVSS 5,8Эксплойта нетEPSS 1 %yahoo · yahoo\! browser26 апр. 2013 г.