peter bassill · operator
$ cve CVE-2007-4034 JSON

CVE-2007-4034 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 13% (pctl 96)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the YDPCTL.YDPControl.1 (aka Yahoo! Installer Plugin for Widgets) ActiveX control before 2007.7.13.3 (20070620) in YDPCTL.dll in Yahoo! Widgets before 4.0.5 allows remote attackers to execute arbitrary code via a long argument to the GetComponentVersion method. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS12.96% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-07-27
Last modified2026-06-16

Affected (1)

VendorProduct
yahoowidgets

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD