CVE-2007-4034
high · 9.3Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.
9.3
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2007-07-27
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| yahoo | widgets | <= 4.0.5 |
Check a specific version with /api/v1/cve/match.
References
- http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html
- http://osvdb.org/37705
- http://secunia.com/advisories/26011
- http://www.kb.cert.org/vuls/id/120760
- http://www.securityfocus.com/bid/25086
- http://www.securitytracker.com/id?1018470
- http://www.vupen.com/english/advisories/2007/2679
- http://help.yahoo.com/l/us/yahoo/widgets/security/security-08.html
- http://osvdb.org/37705
- http://secunia.com/advisories/26011
- http://www.kb.cert.org/vuls/id/120760
- http://www.securityfocus.com/bid/25086
- http://www.securitytracker.com/id?1018470
- http://www.vupen.com/english/advisories/2007/2679
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-4034