CVE-2006-6603: Buffer Overflow
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document. NOTE: some details were obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6603?
CVE-2006-6603 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-6603?
To fix CVE-2006-6603, users should upgrade to the latest version of Yahoo Messenger that addresses this vulnerability.
Which versions of Yahoo Messenger are affected by CVE-2006-6603?
CVE-2006-6603 affects several versions of Yahoo Messenger including 5.0, 5.5, 5.6, 6.0, 7.0, 7.5 and versions up to 8.0.
What is a buffer overflow in the context of CVE-2006-6603?
In CVE-2006-6603, a buffer overflow occurs when the YMMAPI.YMailAttach ActiveX control does not properly handle input, allowing attackers to execute arbitrary code.
Can CVE-2006-6603 be exploited through a web page?
Yes, CVE-2006-6603 can be exploited through a crafted HTML document that targets the vulnerable ActiveX control in Yahoo Messenger.