CVE-2008-2111 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 5.4% (pctl 92)
Patch early
A public exploit exists.
Description
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 5.39% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-399 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-05-07 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| yahoo | yahoo assistant |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Yahoo! Assistant 3.6 - 'yNotifier.dll' ActiveX Control Memory Corruption | 2008-05-06 |
References
- http://secunia.com/advisories/30115
- http://secway.org/advisory/AD20080506EN.txt
- http://www.securityfocus.com/bid/29065
- http://www.securitytracker.com/id?1020004
- http://www.vupen.com/english/advisories/2008/1471/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42233
- http://secunia.com/advisories/30115
- http://secway.org/advisory/AD20080506EN.txt
- http://www.securityfocus.com/bid/29065
- http://www.securitytracker.com/id?1020004
- http://www.vupen.com/english/advisories/2008/1471/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42233
→ the Explorer · watch your stack · NVD