Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-34043
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS…
Serialize
7.0.5+
MEDIUM 6.1
CVE-2019-6035
Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…
Athenz
after 1.8.24
HIGH 7.8
CVE-2017-2253
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13,…
Toolbar
after 8.0.0.6
HIGH 9.3
CVE-2014-7216EPSS 7%
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and poss…
Messenger
after 11.5.0.228
MEDIUM 5.4
CVE-2014-5881
The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows m…
Yahoo Ybox
Mitigation only
MEDIUM 5.8
CVE-2013-4699
The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-…
Yafuoku\!
after 4.3.0
MEDIUM 5.8
CVE-2013-4700
The Yahoo! Japan Shopping application 1.4 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle…
Japan Shopping
after 1.4
MEDIUM 5.0
CVE-2013-4873
The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the…
Tumblr
after 3.4.0
MEDIUM 5.8
CVE-2013-2316
The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL display, a d…
Yahoo\! Browser
after 1.4.3
MEDIUM 5.8
CVE-2013-2307
The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.
Yahoo\! Browser
after 1.4.2
MEDIUM 5.8
CVE-2012-2647
Yahoo! Toolbar 1.0.0.5 and earlier for Chrome and Safari allows remote attackers to modify the configured search URL, and intercept search terms, via…
Toolbar
after 1.0.0.5
MEDIUM 5.1
CVE-2012-0268
Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remot…
Messenger
after 11.5.0.152
HIGH 9.3
CVE-2008-2111EPSS 5%
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in …
Yahoo Assistant
after 3.6
MEDIUM 6.8
CVE-2007-6535
Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary code via a…
Toolbar
Mitigation only
MEDIUM 6.8
CVE-2007-6228
Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to cause a denia…
Toolbar
No fix yet
MEDIUM 5.0
CVE-2007-5017
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attacke…
Messenger
No fix yet
MEDIUM 5.0
CVE-2007-4635
Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, …
Messenger
No fix yet
HIGH 9.3
CVE-2007-4515EPSS 33%
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 al…
Messenger
after 8.1.0.413
HIGH 9.3
CVE-2007-4391EPSS 9%
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application cra…
Messenger
Mitigation only
HIGH 9.3
CVE-2007-4034EPSS 13%
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDP…
Widgets
after 4.0.5
HIGH 7.6
CVE-2007-3928EPSS 6%
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an add…
Messenger
Patch available
MEDIUM 6.0
CVE-2007-3638
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code…
Messenger
No fix yet
HIGH 9.3
CVE-2007-3147EPSS 40%
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute a…
Messenger
Patch available
HIGH 9.3
CVE-2007-3148EPSS 12%
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute a…
Messenger
Patch available
MEDIUM 5.0
CVE-2007-2385
The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers…
Ui Library
Mitigation only
HIGH 9.3
CVE-2007-1680EPSS 8%
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 2007031…
Messenger
Patch available
MEDIUM 5.0
CVE-2007-0868
Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of servi…
Messenger
No fix yet
HIGH 9.3
CVE-2006-6603EPSS 7%
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbit…
Messenger
after 8.0
MEDIUM 5.0
CVE-2006-5563
Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference an…
Messenger
Patch available
MEDIUM 5.0
CVE-2006-3298
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, w…
Messenger
No fix yet