CVE-2007-4515

Scores

EPSS

0.701medium70.1%
0%20%40%60%80%100%

Percentile: 70.1%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-119

Exploits

Exploit ID: 16522

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16522

Exploit ID: 4351

Source: exploitdb

URL: https://www.exploit-db.com/exploits/4351

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: messenger

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:yahoo:messenger:*:*:*:*:*:*:*:*",      "versionEndIncluding": "8.1.0.413",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list