CVE-2007-4034
Yahoo! Installer Plugin for Widgets <2007.7.13.3 - Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4034. PoCs published by lhoang8500.
AI-analyzed exploit summary This exploit targets a heap spray vulnerability in a specific ActiveX control (CLSID:7EC7B6C5-25BD-4586-A641-D2ACBB6629DD) to achieve remote code execution. It uses a combination of heap spraying and a buffer overflow to execute arbitrary shellcode.
Description
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit targets a heap spray vulnerability in a specific ActiveX control (CLSID:7EC7B6C5-25BD-4586-A641-D2ACBB6629DD) to achieve remote code execution. It uses a combination of heap spraying and a buffer overflow to execute arbitrary shellcode.