Vulnerability Name: | CVE-2007-4515 (CCN-36363) | ||||||||
Assigned: | 2007-08-29 | ||||||||
Published: | 2007-08-29 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. Note: some of these details are obtained from third party information. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
7.7 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4515 Source: IDEFENSE Type: Patch, Vendor Advisory 20070830 Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities Source: CCN Type: Yahoo Messenger Web site - Security Updates Yahoo! ActiveX Control Update - buffer overflow in an ActiveX control Source: CONFIRM Type: Patch http://messenger.yahoo.com/security_update.php?id=082907 Source: OSVDB Type: UNKNOWN 37739 Source: CCN Type: SA26579 Yahoo! Messenger YVerInfo.dll ActiveX Control Buffer Overflows Source: SECUNIA Type: Patch, Vendor Advisory 26579 Source: SREASON Type: UNKNOWN 3083 Source: CCN Type: SECTRACK ID: 1018628 Yahoo! Messenger Buffer Overflow in ActiveX Control Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1018628 Source: CCN Type: OSVDB ID: 37739 Yahoo! Messenger ActiveX (YVerInfo.dll) Multiple Method Arbitrary Code Execution Source: CCN Type: OSVDB ID: 45850 Yahoo! Messenger Unspecified File-transfer Packet Handling Remote DoS Source: BID Type: UNKNOWN 25494 Source: CCN Type: BID-25494 Yahoo! Messenger YVerInfo.DLL ActiveX Control Multiple Buffer Overflow Weaknesses Source: VUPEN Type: UNKNOWN ADV-2007-3011 Source: XF Type: UNKNOWN yahoo-messenger-yverinfo-bo(36363) Source: XF Type: UNKNOWN yahoo-messenger-yverinfo-bo(36363) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 08.30.07 Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities Source: CCN Type: Rapid7 Vulnerability and Exploit Database [08-30-2007] Yahoo! Messenger YVerInfo.dll ActiveX Control Buffer Overflow | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |