CVE-2007-6699

AIM PicEditor 9.5.1.8 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6699. PoCs published by Elazar Broad.

AI-analyzed exploit summary This exploit targets multiple buffer overflow vulnerabilities in the AOL Picture Editor ActiveX control (YGPPicEdit.dll) by passing an overly long string to various properties, leading to a denial of service (DoS). The PoC demonstrates the crash via a malicious HTML page but does not achieve arbitrary code execution.

Description

Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy, and (8) UserAgent property values.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Elazar Broad · htmldoswindows
https://www.exploit-db.com/exploits/30936

This exploit targets multiple buffer overflow vulnerabilities in the AOL Picture Editor ActiveX control (YGPPicEdit.dll) by passing an overly long string to various properties, leading to a denial of service (DoS). The PoC demonstrates the crash via a malicious HTML page but does not achieve arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: AOL Picture Editor YGPPicEdit.dll 9.5.1.8
No auth needed
Prerequisites: Victim must visit a malicious HTML page using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019143
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2007/Dec/0561.html
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2007/Dec/0574.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27026
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41198

Scores

EPSS 0.0450
EPSS Percentile 90.3%

Details

CWE
CWE-119
Status published
Products (1)
aol/ygp_piceditor_activex_control 9.5.1.8
Published Feb 04, 2008
Tracked Since Feb 18, 2026