Show filters
198 Total Results
Displaying 101-110 of 198
Sort by:
Attacker Value
Unknown
CVE-2007-1908
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.
0
Attacker Value
Unknown
CVE-2007-1680
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
0
Attacker Value
Unknown
CVE-2006-6995
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter.
0
Attacker Value
Unknown
CVE-2007-0868
Disclosure Date: February 09, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-0768
Disclosure Date: February 06, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-0519
Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.
0
Attacker Value
Unknown
CVE-2006-6728
Disclosure Date: December 26, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the info request mechanism in LAN Messenger before 1.5.1.2 allows remote attackers to cause a denial of service (application crash) or transmit spam via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-6603
Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document. NOTE: some details were obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-6252
Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
0
Attacker Value
Unknown
CVE-2006-5652
Disclosure Date: November 03, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.
0