CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
11449 | CVE-2005-0243 | Candidate | Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions. | Assigned (20050208) | None (candidate not yet proposed) | View | |
19402 | CVE-2006-3298 | Candidate | Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll. | Assigned (20060628) | None (candidate not yet proposed) | View | |
27992 | CVE-2007-4635 | Candidate | Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20070831) | None (candidate not yet proposed) | View | |
6048 | CVE-2002-1664 | Candidate | Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user"s buddy list and possibly obtain sensitive information. | Assigned (20050528) | None (candidate not yet proposed) | View | |
21079 | CVE-2006-4975 | Candidate | Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service. | Assigned (20060924) | None (candidate not yet proposed) | View |
Page 20897 of 20943, showing 5 records out of 104715 total, starting on record 104481, ending on 104485