Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-1680

Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.515
EPSS Ranking 97.8%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2007-1680
  • Yahoo » Messenger » Version: 8.0
    cpe:2.3:a:yahoo:messenger:8.0
  • Yahoo » Messenger » Version: 8.0.0.863
    cpe:2.3:a:yahoo:messenger:8.0.0.863
  • Yahoo » Messenger » Version: 8.0_2005.1.1.4
    cpe:2.3:a:yahoo:messenger:8.0_2005.1.1.4
  • Yahoo » Messenger » Version: 8.1.0.209
    cpe:2.3:a:yahoo:messenger:8.1.0.209
  • Yahoo » Messenger » Version: 8.1.0.239
    cpe:2.3:a:yahoo:messenger:8.1.0.239


Contact Us

Shodan ® - All rights reserved