CVE-2014-7216: Buffer Overflow
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7216?
CVE-2014-7216 is rated as a high severity vulnerability due to the potential for remote code execution and denial of service.
How do I fix CVE-2014-7216?
To address CVE-2014-7216, upgrade Yahoo Messenger to version 11.5.0.229 or later.
What software is affected by CVE-2014-7216?
CVE-2014-7216 affects Yahoo Messenger version 11.5.0.228 and earlier.
What type of attack can be executed through CVE-2014-7216?
CVE-2014-7216 allows attackers to exploit buffer overflows leading to denial of service and potentially arbitrary code execution.
Are there any workarounds for CVE-2014-7216?
Currently, the best workaround for CVE-2014-7216 is to uninstall Yahoo Messenger if immediate upgrade is not feasible.