Lucene search

K
cve[email protected]CVE-2012-0268
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-0268

2022-10-0316:15:38
CWE-189
web.nvd.nist.gov
27
cve-2012-0268
integer overflow
cyimage::loadjpg
yimage.dll
yahoo! messenger
remote code execution
crafted jpg image
nvd
heap-based buffer overflow

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.4%

Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.

Affected configurations

NVD
Node
yahoomessengerRange≀11.5.0.152
OR
yahoomessengerMatch0.99.17-1
OR
yahoomessengerMatch1.0
OR
yahoomessengerMatch1.0.4
OR
yahoomessengerMatch1.0.6
OR
yahoomessengerMatch2.0.1.4
OR
yahoomessengerMatch3.0
OR
yahoomessengerMatch3.0.1
OR
yahoomessengerMatch3.0.1beta-35554
OR
yahoomessengerMatch3.5
OR
yahoomessengerMatch4.0
OR
yahoomessengerMatch4.1
OR
yahoomessengerMatch5.0
OR
yahoomessengerMatch5.0.1046
OR
yahoomessengerMatch5.0.1065
OR
yahoomessengerMatch5.0.1232
OR
yahoomessengerMatch5.5
OR
yahoomessengerMatch5.5.1249
OR
yahoomessengerMatch5.6
OR
yahoomessengerMatch5.6.0.1347
OR
yahoomessengerMatch5.6.0.1351
OR
yahoomessengerMatch5.6.0.1355
OR
yahoomessengerMatch5.6.0.1356
OR
yahoomessengerMatch5.6.0.1358
OR
yahoomessengerMatch6.0
OR
yahoomessengerMatch6.0.0.1643
OR
yahoomessengerMatch6.0.0.1750
OR
yahoomessengerMatch6.0.0.1921
OR
yahoomessengerMatch6.1
OR
yahoomessengerMatch7.0
OR
yahoomessengerMatch7.0.0.426
OR
yahoomessengerMatch7.0.0.437
OR
yahoomessengerMatch7.0.438
OR
yahoomessengerMatch7.5
OR
yahoomessengerMatch7.5.0.814
OR
yahoomessengerMatch8.0
OR
yahoomessengerMatch8.0.0.505
OR
yahoomessengerMatch8.0.0.508
OR
yahoomessengerMatch8.0.0.701
OR
yahoomessengerMatch8.0.0.716
OR
yahoomessengerMatch8.0.0.863
OR
yahoomessengerMatch8.0.1
OR
yahoomessengerMatch8.0_2005.1.1.4
OR
yahoomessengerMatch8.1
OR
yahoomessengerMatch8.1.0.195
OR
yahoomessengerMatch8.1.0.209
OR
yahoomessengerMatch8.1.0.239
OR
yahoomessengerMatch8.1.0.244
OR
yahoomessengerMatch8.1.0.249
OR
yahoomessengerMatch8.1.0.401
OR
yahoomessengerMatch8.1.0.402
OR
yahoomessengerMatch8.1.0.413
OR
yahoomessengerMatch8.1.0.416
OR
yahoomessengerMatch8.1.0.419
OR
yahoomessengerMatch8.1.0.421
OR
yahoomessengerMatch9.0.0.797beta
OR
yahoomessengerMatch9.0.0.907beta
OR
yahoomessengerMatch9.0.0.922beta
OR
yahoomessengerMatch9.0.0.1389beta
OR
yahoomessengerMatch9.0.0.1912
OR
yahoomessengerMatch9.0.0.2018
OR
yahoomessengerMatch9.0.0.2034
OR
yahoomessengerMatch9.0.0.2112
OR
yahoomessengerMatch9.0.0.2123
OR
yahoomessengerMatch9.0.0.2128
OR
yahoomessengerMatch9.0.0.2133
OR
yahoomessengerMatch9.0.0.2136
OR
yahoomessengerMatch9.0.0.2152
OR
yahoomessengerMatch9.0.0.2160
OR
yahoomessengerMatch9.0.0.2161
OR
yahoomessengerMatch9.0.0.2162
OR
yahoomessengerMatch10.0.0.331pre-alpha
OR
yahoomessengerMatch10.0.0.525beta
OR
yahoomessengerMatch10.0.0.542beta
OR
yahoomessengerMatch10.0.0.1102
OR
yahoomessengerMatch10.0.0.1241
OR
yahoomessengerMatch10.0.0.1258
OR
yahoomessengerMatch10.0.0.1264
OR
yahoomessengerMatch10.0.0.1267
OR
yahoomessengerMatch10.0.0.1270
OR
yahoomessengerMatch11.0.0.1751
OR
yahoomessengerMatch11.0.0.2009
OR
yahoomessengerMatch11.0.0.2014

5.1 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.4%