← Vulnerability feed

Vulnerability record · CVE-2007-4391 · published 17 August 2007

CVE-2007-4391: Yahoo messenger improper input validation vulnerability

Yahoo · Messenger

Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by sending an "invite to view my webcam" request, and then injecting a DLL into the attacker's peer Yahoo! Messenger application when this request is accepted.

9.3 CVSS 2.0 High EPSS 9.3% · top 4.8% CWE-20 · Improper input validationCWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
9.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by sending an "invite to view my webcam" request, and then injecting a DLL into the attacker's peer Yahoo! Messenger application when this request is accepted.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4391 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-7216Yahoo messenger memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and poss…EPSS 6.8%9.3CVE-2007-4515Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 al…EPSS 33%9.3CVE-2007-3147Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute a…EPSS 40%9.3CVE-2007-3148Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute a…EPSS 12%9.3CVE-2007-1680Yahoo messenger vulnerabilityStack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 2007031…EPSS 8.4%9.3CVE-2006-6603Yahoo messenger vulnerabilityBuffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbit…EPSS 6.6%7.6CVE-2007-3928Yahoo messenger memory buffer overflow vulnerabilityBuffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an add…EPSS 5.7%7.5CVE-2005-0737Yahoo messenger vulnerabilityBuffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2007-4391), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.