VulnerabilityModified
CVE-2007-4034
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo!
HIGH 9.3EPSS 13.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 12.96% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- yahoo/widgets
- Source
- cve@mitre.org
References
- http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.htmlPatch, Vendor Advisory
- http://osvdb.org/37705
- http://secunia.com/advisories/26011Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/120760US Government Resource
- http://www.securityfocus.com/bid/25086Exploit, Patch
- http://www.securitytracker.com/id?1018470
- http://www.vupen.com/english/advisories/2007/2679
- http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.htmlPatch, Vendor Advisory
- http://osvdb.org/37705
- http://secunia.com/advisories/26011Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/120760US Government Resource
- http://www.securityfocus.com/bid/25086Exploit, Patch
- http://www.securitytracker.com/id?1018470
- http://www.vupen.com/english/advisories/2007/2679
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.