EIP-2026-116632
PRE-CVEYahoo! CD Player - ActiveX Control 'open()' Method Stack Buffer Overflow
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-116632. PoCs published by shinnai.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in the Yahoo! CD Player ActiveX control by passing an overly long string to the 'open' method, leading to arbitrary code execution or denial-of-service. The PoC uses VBScript to trigger the vulnerability via the ActiveX control's CLSID.
Description
Yahoo! CD Player - ActiveX Control 'open()' Method Stack Buffer Overflow
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in the Yahoo! CD Player ActiveX control by passing an overly long string to the 'open' method, leading to arbitrary code execution or denial-of-service. The PoC uses VBScript to trigger the vulnerability via the ActiveX control's CLSID.