Yahoo's vulnerability profile spans a moderately represented portfolio of web services, messaging platforms, and client-side applications—including Messenger, YUI libraries, browser toolbars, and media software—that collectively served millions of users over extended deployment windows. The exposure recurs across application-layer and memory-safety weakness classes, with a concentration in cross-site scripting, input validation failures, buffer-boundary violations, and information disclosure, reflecting the complexity of browser integration and web client codebases. Public exploit code has frequently been developed for vulnerabilities in this vendor's products, particularly in widely distributed client-side components that offer scale and longevity as attack vectors. Defenders should prioritize inventory of legacy Yahoo client software and web-service integrations, as older endpoints may remain vulnerable and unmaintained; live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yahoo over time
Signals from CVEs in this vendor scope (67 CVEs).
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3147HIGH Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server | Jun 11, 2007 | 9.3 | 67 | NO | YES |
CVE-2007-4515HIGH Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execut | Aug 31, 2007 | 9.3 | 60 | NO | YES |
CVE-2007-4391HIGH Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field | Aug 17, 2007 | 9.3 | 43 | NO | YES |
CVE-2007-3148HIGH Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server | Jun 11, 2007 | 9.3 | 42 | NO | YES |
CVE-2007-4034HIGH Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets befor | Jul 27, 2007 | 9.3 | 41 | NO | YES |
CVE-2008-2111HIGH The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that tr | May 7, 2008 | 9.3 | 35 | NO | YES |
CVE-2005-0737HIGH Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode. | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2002-0031MEDIUM Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getim | Jul 26, 2002 | 4.6 | 28 | NO | YES |
CVE-2026-34043HIGH Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU e | Mar 31, 2026 | 7.5 | 27 | NO | NO |
CVE-2014-7216HIGH Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via | Sep 11, 2015 | 9.3 | 27 | NO | NO |
Signals from CVEs in this vendor scope (67 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yahoo.
Media articles that mention a CVE ID that affects a product developed by Yahoo — matched by CVE ID, not by vendor name.