Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
7.5 |
|
AV:N/AC:L/Au:N/C:P/I:P/A:P |
nvd@nist.gov |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 25196
Publication date : 2005-03-07 23h00 +00:00
Author : Mehrtash Mallahzadeh
EDB Verified : Yes
source: https://www.securityfocus.com/bid/12750/info
It has been reported that a remote buffer overflow vulnerability affects Yahoo! Messenger. This issue is due to a failure of the application to securely copy user-supplied input into finite process buffers.
It is likely that the attacker must be in the contact list of an unsuspecting user to exploit this issue. It should be noted that the details surrounding this issue are not clear; this BID will be updated as more details are released.
An attacker may leverage this issue to execute arbitrary code in the context of an unsuspecting user running a vulnerable version of the affected application.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/25196.zip
Products Mentioned
Configuraton 0
Yahoo>>Messenger >> Version 4.0
Yahoo>>Messenger >> Version 5.0
Yahoo>>Messenger >> Version 5.0.1046
Yahoo>>Messenger >> Version 5.0.1065
Yahoo>>Messenger >> Version 5.0.1232
Yahoo>>Messenger >> Version 5.5
Yahoo>>Messenger >> Version 5.5.1249
Yahoo>>Messenger >> Version 5.6
Yahoo>>Messenger >> Version 5.6.0.1347
Yahoo>>Messenger >> Version 5.6.0.1351
Yahoo>>Messenger >> Version 5.6.0.1355
Yahoo>>Messenger >> Version 5.6.0.1356
Yahoo>>Messenger >> Version 5.6.0.1358
Yahoo>>Messenger >> Version 6.0
Yahoo>>Messenger >> Version 6.0.0.1643
Yahoo>>Messenger >> Version 6.0.0.1750
Yahoo>>Messenger >> Version 6.0.0.1921
References