Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yahoo

First CVE: Oct 1, 1999Active for: 27 yearsTotal CVEs: 67
32.1
VTI Score
Medium

Yahoo's vulnerability profile spans a moderately represented portfolio of web services, messaging platforms, and client-side applications—including Messenger, YUI libraries, browser toolbars, and media software—that collectively served millions of users over extended deployment windows. The exposure recurs across application-layer and memory-safety weakness classes, with a concentration in cross-site scripting, input validation failures, buffer-boundary violations, and information disclosure, reflecting the complexity of browser integration and web client codebases. Public exploit code has frequently been developed for vulnerabilities in this vendor's products, particularly in widely distributed client-side components that offer scale and longevity as attack vectors. Defenders should prioritize inventory of legacy Yahoo client software and web-service integrations, as older endpoints may remain vulnerable and unmaintained; live severity, exploitation, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
67
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yahoo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 1999
26 years ago
Most Recent CVE
Mar 31, 2026
115 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (67 CVEs).

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-3147HIGH
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server
Jun 11, 20079.367NOYES
CVE-2007-4515HIGH
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execut
Aug 31, 20079.360NOYES
CVE-2007-4391HIGH
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field
Aug 17, 20079.343NOYES
CVE-2007-3148HIGH
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server
Jun 11, 20079.342NOYES
CVE-2007-4034HIGH
Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets befor
Jul 27, 20079.341NOYES
CVE-2008-2111HIGH
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that tr
May 7, 20089.335NOYES
CVE-2005-0737HIGH
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
May 2, 20057.529NOYES
CVE-2002-0031MEDIUM
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getim
Jul 26, 20024.628NOYES
CVE-2026-34043HIGH
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU e
Mar 31, 20267.527NONO
CVE-2014-7216HIGH
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via
Sep 11, 20159.327NONO
View all 67 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products67 CVEs
67%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (1.5%)
Network2 (3.0%)
Unknown64 (95.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (4.5%)
High0 (0.0%)
Unknown64 (95.5%)
User Interaction
None1 (1.5%)
Unknown64 (95.5%)
Required2 (3.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (4.5%)
Unknown64 (95.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (67 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
21 CVEs
31.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yahoo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yahoo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yahoo's Products

View all 4 CNAs →

Top CWEs