RSS   Vulnerabilities for 'Widgets'   RSS

2007-07-27
 
CVE-2007-4034

CWE-119
 

 
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.

 

 >>> Vendor: Yahoo 15 Products
Pager
Messenger
Toolbar
Audio conferencing activex control
Ui library
Widgets
Music jukebox
Yahoo assistant
YUI
Yahoo! browser
Tumblr
Yafuoku!
Japan shopping
Yahoo ybox
Athenz


Copyright 2024, cxsecurity.com

 

Back to Top