Kaspersky ID:
KLA10664
Detect Date:
09/11/2015
Updated:
06/03/2020

Description

Buffer overflow vulnerability was found in Yahoo! Messenger. By exploiting this vulnerability malicious users can cause denial of service or execute arbitrary code. This vulnerability can be exploited remotely via a specially designed emoticons.xml file.


Technical details

Vulnerability caused by unrestricted emoticons parameters reading. This vulnerability can be exploited via changing content of emoticons.xml at title and shortcut elements. Changed emoticons file can be distributed via custom emoticons pack. At this moment vendor does not plan to release special patch for this vulnerability.

Original advisories

Related products

CVE list

  • CVE-2014-7216
    critical

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.