VulnerabilityModified
CVE-2007-3928
Buffer overflow in Yahoo!
HIGH 7.6EPSS 5.66%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 5.66% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- yahoo/messenger
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064669.html
- http://secunia.com/advisories/26066Patch, Vendor Advisory
- http://securityreason.com/securityalert/2906
- http://www.securityfocus.com/bid/24926
- http://www.securitytracker.com/id?1018398
- http://www.xdisclose.com/advisory/XD100002.htmlPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35434
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-July/064669.html
- http://secunia.com/advisories/26066Patch, Vendor Advisory
- http://securityreason.com/securityalert/2906
- http://www.securityfocus.com/bid/24926
- http://www.securitytracker.com/id?1018398
- http://www.xdisclose.com/advisory/XD100002.htmlPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35434
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.