Skip to main content

Vendor archive

yahoo CVEs

Beta · best-effort

67 CVEs tagged to vendor yahoo9 Critical, 8 High, 46 Medium, 4 Low, 0 Unrated.

CVE-2026-34043

Published Mar 31, 2026

Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2019-6035

Published Dec 26, 2019

Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted pag…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2253

Published Jul 17, 2017

Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an atta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7216

Published Sep 11, 2015

Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5881

Published Sep 11, 2014

The Yahoo! Japan Box (aka jp.co.yahoo.android.ybox) application 1.5.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6853

Published Jan 26, 2014

Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6780

Published Nov 13, 2013

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4700

Published Aug 21, 2013

The Yahoo! Japan Shopping application 1.4 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers an…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4699

Published Aug 21, 2013

The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4942

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in flashuploader.swf in the Uploader component in Yahoo! YUI 3.5.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4941

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 3.2.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4940

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.10.2, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4939

Published Jul 29, 2013

Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x befo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4873

Published Jul 18, 2013

The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2316

Published Jun 3, 2013

The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL display, a different vulnerability than CV…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2307

Published Apr 26, 2013

The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5883

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.9.0, as used in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5882

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5881

Published Nov 16, 2012

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vector…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2645

Published Jul 16, 2012

The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive informat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0268

Published Jan 19, 2012

Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitra…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4710

Published Jan 28, 2011

Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4209

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4208

Published Nov 7, 2010

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 67 CVEsPage 1 of 3