CVE-2007-3148

EXPLOITED

Yahoo Messenger - Memory Corruption

Title source: rule

Description

Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Excepti0n · cremotewindows
https://www.exploit-db.com/exploits/4052
exploitdb WORKING POC VERIFIED
by Excepti0n · htmlremotewindows
https://www.exploit-db.com/exploits/4043

Scores

EPSS 0.6259
EPSS Percentile 98.4%

Details

VulnCheck KEV 2010-05-01
CWE
CWE-119
Status published
Products (6)
yahoo/messenger 2.0.1.4
yahoo/messenger 8.0
yahoo/messenger 8.0.0.863
yahoo/messenger 8.0.1
yahoo/messenger 8.0_2005.1.1.4
yahoo/messenger 8.1.0.249
Published Jun 11, 2007
Tracked Since Feb 18, 2026