← Vulnerability feed

Vulnerability record · CVE-2007-3148 · published 11 June 2007

CVE-2007-3148: Yahoo messenger memory buffer overflow vulnerability

Yahoo · Messenger

Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.

9.3 CVSS 2.0 High EPSS 12% · top 3.9% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063819.html Exploit
http://messenger.yahoo.com/security_update.php?id=060707 Patch
http://osvdb.org/37081
http://research.eeye.com/html/advisories/published/AD20070608.html Vendor Advisory
http://research.eeye.com/html/advisories/upcoming/20070605.html Vendor Advisory
http://secunia.com/advisories/25547 PatchVendor Advisory
http://securitytracker.com/id?1018204 Exploit
http://www.kb.cert.org/vuls/id/932217 PatchUS Government Resource
http://www.securityfocus.com/archive/1/470861/100/0/threaded
http://www.securityfocus.com/bid/24341
http://www.securityfocus.com/bid/24355 Exploit
http://www.securitytracker.com/id?1018203
http://www.vupen.com/english/advisories/2007/2094
https://exchange.xforce.ibmcloud.com/vulnerabilities/34759
https://www.exploit-db.com/exploits/4043
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063819.html Exploit
http://messenger.yahoo.com/security_update.php?id=060707 Patch
http://osvdb.org/37081
http://research.eeye.com/html/advisories/published/AD20070608.html Vendor Advisory
http://research.eeye.com/html/advisories/upcoming/20070605.html Vendor Advisory
http://secunia.com/advisories/25547 PatchVendor Advisory
http://securitytracker.com/id?1018204 Exploit
http://www.kb.cert.org/vuls/id/932217 PatchUS Government Resource
http://www.securityfocus.com/archive/1/470861/100/0/threaded
http://www.securityfocus.com/bid/24341
http://www.securityfocus.com/bid/24355 Exploit
http://www.securitytracker.com/id?1018203
http://www.vupen.com/english/advisories/2007/2094
https://exchange.xforce.ibmcloud.com/vulnerabilities/34759
https://www.exploit-db.com/exploits/4043

Track CVE-2007-3148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-7216Yahoo messenger memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and poss…EPSS 6.8%9.3CVE-2007-4515Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 al…EPSS 33%9.3CVE-2007-4391Yahoo messenger improper input validation vulnerabilityHeap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application cra…EPSS 9.3%9.3CVE-2007-3147Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute a…EPSS 40%9.3CVE-2007-1680Yahoo messenger vulnerabilityStack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 2007031…EPSS 8.4%9.3CVE-2006-6603Yahoo messenger vulnerabilityBuffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbit…EPSS 6.6%7.6CVE-2007-3928Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an add…EPSS 5.7%7.5CVE-2005-0737Yahoo messenger vulnerabilityBuffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2007-3148), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.