Vulnerability Description
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yahoo | Messenger | <= 11.5.0.228 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/133443/Yahoo-Messenger-11.5.0.228-Buffer-Ov
- http://seclists.org/fulldisclosure/2015/Sep/24
- http://www.securityfocus.com/archive/1/536390/100/0/threaded
- http://www.securitytracker.com/id/1033544
- https://hackerone.com/reports/10767
- https://www.rcesecurity.com/2015/09/cve-2014-7216-a-journey-through-yahoos-bug-bExploit
- http://packetstormsecurity.com/files/133443/Yahoo-Messenger-11.5.0.228-Buffer-Ov
- http://seclists.org/fulldisclosure/2015/Sep/24
- http://www.securityfocus.com/archive/1/536390/100/0/threaded
- http://www.securitytracker.com/id/1033544
- https://hackerone.com/reports/10767
- https://www.rcesecurity.com/2015/09/cve-2014-7216-a-journey-through-yahoos-bug-bExploit
FAQ
What is CVE-2014-7216?
CVE-2014-7216 is a vulnerability with a CVSS score of 9.3 (HIGH). Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or...
How severe is CVE-2014-7216?
CVE-2014-7216 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7216?
Check the references section above for vendor advisories and patch information. Affected products include: Yahoo Messenger.