Show filters
67 Total Results
Displaying 21-30 of 67
Sort by:
Attacker Value
Unknown
CVE-2012-2645
Disclosure Date: July 16, 2012 (last updated October 04, 2023)
The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
0
Attacker Value
Unknown
CVE-2012-0268
Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2010-4710
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.
0
Attacker Value
Unknown
CVE-2010-4207
Disclosure Date: November 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.
0
Attacker Value
Unknown
CVE-2010-4208
Disclosure Date: November 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/assets/uploader.swf.
0
Attacker Value
Unknown
CVE-2010-4209
Disclosure Date: November 07, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
0
Attacker Value
Unknown
CVE-2009-4171
Disclosure Date: December 02, 2009 (last updated October 04, 2023)
An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument.
0
Attacker Value
Unknown
CVE-2008-2111
Disclosure Date: May 07, 2008 (last updated October 04, 2023)
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2008-0625
Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method.
0
Attacker Value
Unknown
CVE-2008-0624
Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623.
0