Lucene search

K
cve[email protected]CVE-2007-4515
HistoryAug 31, 2007 - 10:17 p.m.

CVE-2007-4515

2007-08-3122:17:00
CWE-119
web.nvd.nist.gov
21
cve-2007-4515
buffer overflow
yverinfo.dll
activex control
yahoo! messenger
remote code execution
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.844 High

EPSS

Percentile

98.5%

Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
yahoomessengerRange8.1.0.413

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.844 High

EPSS

Percentile

98.5%