RSS   Vulnerabilities for 'Widgets'   RSS

2007-07-27
 
CVE-2007-4034

CWE-119
 

 
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.

 

 >>> Vendor: Yahoo 14 Products
Pager
Messenger
Audio conferencing activex control
Ui library
Widgets
Toolbar
Music jukebox
Yahoo assistant
YUI
Yahoo! browser
Tumblr
Yafuoku!
Japan shopping
Yahoo ybox


Copyright 2019, cxsecurity.com

 

Back to Top