https://seclists.org/fulldisclosure/2007/Jun/131
https://seclists.org/fulldisclosure/2007/Jun/133
https://www.securityfocus.com/archive/1/470861/30/0/threaded
Severity: High
ID: 25459
File Name: yahoo_msgr_webcam_activex_buffer_overflows.nasl
Version: 1.21
Type: local
Agent: windows
Family: Windows
Published: 6/11/2007
Updated: 4/11/2022
Configuration: Enable thorough checks
Supported Sensors: Nessus Agent, Nessus
Risk Factor: High
Score: 7.4
Risk Factor: High
Base Score: 9.3
Temporal Score: 7.7
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
CPE: cpe:/a:yahoo:messenger
Required KB Items: SMB/Registry/Enumerated
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 6/8/2007
Vulnerability Publication Date: 6/7/2007
Core Impact
Metasploit (Yahoo! Messenger 8.1.0.249 ActiveX Control Buffer Overflow)
CVE: CVE-2007-3147, CVE-2007-3148
CWE: 119