HomeYahooCVE-2007-4034

CVE-2007-4034

UNKNOWN
9.3CVSS
Published: 2007-07-27
Updated: 2025-04-09
AI Analysis

Description

Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.

CVSS Metrics

Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector
network
Access Cmplx
medium
Auth
none
Confidentiality
complete
Integrity
complete
Availability
complete
Weaknesses
CWE-119

Metadata

Primary Vendor
YAHOO
Published
7/27/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

yahoo : widgets

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief