Stack-Based Buffer Overflow in Yahoo! Messenger by Yahoo
CVE-2014-7216

Currently unrated

Key Information:

Vendor

Yahoo

Status
Vendor
CVE Published:
11 September 2015

What is CVE-2014-7216?

Yahoo! Messenger versions up to 11.5.0.228 are susceptible to multiple stack-based buffer overflow vulnerabilities. These flaws can be exploited by remote attackers through specially crafted inputs in the emoticons.xml file, notably using the shortcut or title keys. Successful exploitation could lead to a denial of service by crashing the application, and it may also allow attackers to execute arbitrary code, posing significant security risks to users.

References

EPSS Score

6% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.