yahoo kayıtları
yahoo üreticisine ait 67 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %3
- Pre-auth RCE
- 20
- Düzeltme kaydı olan
- %9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-310 Cryptographic Issues3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation2
- CWE-255 Credentials Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
67 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2007-3147Silahlaştırılmış | Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to yahoo · messenger · CWE-119 | Kritik9,3 | — | %40,4 | 11 Haz 2007 |
47Planlayın | CVE-2007-4515Silahlaştırılmış | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1yahoo · messenger · CWE-119 | Kritik9,3 | — | %33,0 | 31 Ağu 2007 |
41Planlayın | CVE-2007-4034Kavram kanıtı | Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (2007062yahoo · widgets · CWE-119 | Kritik9,3 | — | %13,0 | 27 Tem 2007 |
41Planlayın | CVE-2007-3148Kavram kanıtı | Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to yahoo · messenger · CWE-119 | Kritik9,3 | — | %12,3 | 11 Haz 2007 |
40Planlayın | CVE-2007-4391Kavram kanıtı | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (applicyahoo · messenger · CWE-20 | Kritik9,3 | — | %9,3 | 17 Ağu 2007 |
40Planlayın | CVE-2007-1680İstismar yok | Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger beforyahoo · messenger | Kritik9,3 | — | %8,4 | 5 Nis 2007 |
39İzleyin | CVE-2014-7216İstismar yok | Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash)yahoo · messenger · CWE-119 | Kritik9,3 | — | %6,8 | 11 Eyl 2015 |
39İzleyin | CVE-2006-6603İstismar yok | Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execyahoo · messenger | Kritik9,3 | — | %6,6 | 15 Ara 2006 |
39İzleyin | CVE-2008-2111Kavram kanıtı | The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified veyahoo · yahoo assistant · CWE-399 | Kritik9,3 | — | %5,4 | 7 May 2008 |
32İzleyin | CVE-2002-0320İstismar yok | Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long yahoo · messenger | Yüksek7,5 | — | %7,0 | 25 Haz 2002 |
32İzleyin | CVE-2007-3928İstismar yok | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address yahoo · messenger · CWE-119 | Yüksek7,6 | — | %5,7 | 20 Tem 2007 |
31İzleyin | CVE-2002-1665İstismar yok | Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute ayahoo · messenger | Yüksek7,5 | — | %4,4 | 31 Ara 2002 |
31İzleyin | CVE-2005-0737Kavram kanıtı | Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.yahoo · messenger | Yüksek7,5 | — | %4,1 | 2 May 2005 |
31İzleyin | CVE-2002-0032İstismar yok | Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymyahoo · messenger | Yüksek7,5 | — | %3,9 | 26 Tem 2002 |
31İzleyin | CVE-2004-0043İstismar yok | Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly yahoo · messenger | Yüksek7,5 | — | %3,6 | 3 Şub 2004 |
31İzleyin | CVE-2017-2253İstismar yok | Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior toyahoo · toolbar · CWE-426 | Yüksek7,8 | — | %1,1 | 17 Tem 2017 |
30İzleyin | CVE-2002-0322İstismar yok | Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.yahoo · messenger | Yüksek7,5 | — | %1,6 | 25 Haz 2002 |
30İzleyin | CVE-2026-34043İstismar yok | Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objectsyahoo · serialize · CWE-400 | Yüksek7,5 | — | %0,6 | 30 Mar 2026 |
28İzleyin | CVE-2007-6228Kavram kanıtı | Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to causyahoo · toolbar · CWE-119 | Orta6,8 | — | %2,1 | 4 Ara 2007 |
28İzleyin | CVE-2007-6535İstismar yok | Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary cyahoo · toolbar · CWE-119 | Orta6,8 | — | %1,9 | 27 Ara 2007 |
26İzleyin | CVE-2002-1664İstismar yok | Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensityahoo · messenger | Orta6,4 | — | %3,2 | 31 Ara 2002 |
25İzleyin | CVE-2007-3638Kavram kanıtı | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbityahoo · messenger · CWE-119 | Orta6,0 | — | %2,4 | 9 Tem 2007 |
24İzleyin | CVE-2019-6035İstismar yok | Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishyahoo · athenz · CWE-601 | Orta6,1 | — | %1,1 | 26 Ara 2019 |
23İzleyin | CVE-2013-2316İstismar yok | The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL disyahoo · yahoo\! browser | Orta5,8 | — | %1,5 | 3 Haz 2013 |
23İzleyin | CVE-2013-2307İstismar yok | The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.yahoo · yahoo\! browser | Orta5,8 | — | %1,5 | 26 Nis 2013 |
- CVE-2007-314749Planlayın
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to
KritikCVSS 9,3SilahlaştırılmışEPSS %40yahoo · messenger11 Haz 2007
- CVE-2007-451547Planlayın
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1
KritikCVSS 9,3SilahlaştırılmışEPSS %33yahoo · messenger31 Ağu 2007
- CVE-2007-403441Planlayın
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (2007062
KritikCVSS 9,3Kavram kanıtıEPSS %13yahoo · widgets27 Tem 2007
- CVE-2007-314841Planlayın
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to
KritikCVSS 9,3Kavram kanıtıEPSS %12yahoo · messenger11 Haz 2007
- CVE-2007-439140Planlayın
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (applic
KritikCVSS 9,3Kavram kanıtıEPSS %9yahoo · messenger17 Ağu 2007
- CVE-2007-168040Planlayın
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger befor
KritikCVSS 9,3İstismar yokEPSS %8yahoo · messenger5 Nis 2007
- CVE-2014-721639İzleyin
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash)
KritikCVSS 9,3İstismar yokEPSS %7yahoo · messenger11 Eyl 2015
- CVE-2006-660339İzleyin
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to exec
KritikCVSS 9,3İstismar yokEPSS %7yahoo · messenger15 Ara 2006
- CVE-2008-211139İzleyin
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified ve
KritikCVSS 9,3Kavram kanıtıEPSS %5yahoo · yahoo assistant7 May 2008
- CVE-2002-032032İzleyin
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long
YüksekCVSS 7,5İstismar yokEPSS %7yahoo · messenger25 Haz 2002
- CVE-2007-392832İzleyin
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address
YüksekCVSS 7,6İstismar yokEPSS %6yahoo · messenger20 Tem 2007
- CVE-2002-166531İzleyin
Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute a
YüksekCVSS 7,5İstismar yokEPSS %4yahoo · messenger31 Ara 2002
- CVE-2005-073731İzleyin
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
YüksekCVSS 7,5Kavram kanıtıEPSS %4yahoo · messenger2 May 2005
- CVE-2002-003231İzleyin
Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ym
YüksekCVSS 7,5İstismar yokEPSS %4yahoo · messenger26 Tem 2002
- CVE-2004-004331İzleyin
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly
YüksekCVSS 7,5İstismar yokEPSS %4yahoo · messenger3 Şub 2004
- CVE-2017-225331İzleyin
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to
YüksekCVSS 7,8İstismar yokEPSS %1yahoo · toolbar17 Tem 2017
- CVE-2002-032230İzleyin
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.
YüksekCVSS 7,5İstismar yokEPSS %2yahoo · messenger25 Haz 2002
- CVE-2026-3404330İzleyin
Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
YüksekCVSS 7,5İstismar yokEPSS %1yahoo · serialize30 Mar 2026
- CVE-2007-622828İzleyin
Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to caus
OrtaCVSS 6,8Kavram kanıtıEPSS %2yahoo · toolbar4 Ara 2007
- CVE-2007-653528İzleyin
Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary c
OrtaCVSS 6,8İstismar yokEPSS %2yahoo · toolbar27 Ara 2007
- CVE-2002-166426İzleyin
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensit
OrtaCVSS 6,4İstismar yokEPSS %3yahoo · messenger31 Ara 2002
- CVE-2007-363825İzleyin
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbit
OrtaCVSS 6,0Kavram kanıtıEPSS %2yahoo · messenger9 Tem 2007
- CVE-2019-603524İzleyin
Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phish
OrtaCVSS 6,1İstismar yokEPSS %1yahoo · athenz26 Ara 2019
- CVE-2013-231623İzleyin
The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL dis
OrtaCVSS 5,8İstismar yokEPSS %2yahoo · yahoo\! browser3 Haz 2013
- CVE-2013-230723İzleyin
The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.
OrtaCVSS 5,8İstismar yokEPSS %1yahoo · yahoo\! browser26 Nis 2013