{"api_version":"1","generated_at":"2026-07-23T09:12:39+00:00","cve":"CVE-2007-1680","urls":{"html":"https://cve.report/CVE-2007-1680","api":"https://cve.report/api/cve/CVE-2007-1680.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1680","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1680"},"summary":{"title":"CVE-2007-1680","description":"Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-04-06 01:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/23291","name":"http://www.securityfocus.com/bid/23291","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Yahoo! Messenger Audio Conferencing ActiveX Control Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/2523","name":"http://securityreason.com/securityalert/2523","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1017867","name":"http://www.securitytracker.com/id?1017867","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Yahoo! Messenger Buffer Overflow in AudioConf ActiveX Control Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-07-012.html","name":"http://www.zerodayinitiative.com/advisories/ZDI-07-012.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ZDI-07-012","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://messenger.yahoo.com/security_update.php?id=031207","name":"http://messenger.yahoo.com/security_update.php?id=031207","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Security Update - Yahoo! Messenger","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/388377","name":"http://www.kb.cert.org/vuls/id/388377","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#388377","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1219","name":"http://www.vupen.com/english/advisories/2007/1219","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/464607/100/0/threaded","name":"http://www.securityfocus.com/archive/1/464607/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33408","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33408","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/34319","name":"http://osvdb.org/34319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/24742","name":"http://secunia.com/advisories/24742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1680","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1680","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yahoo","cpe5":"messenger","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yahoo","cpe5":"messenger","cpe6":"8.0.0.863","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yahoo","cpe5":"messenger","cpe6":"8.0_2005.1.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yahoo","cpe5":"messenger","cpe6":"8.1.0.209","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1680","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yahoo","cpe5":"messenger","cpe6":"8.1.0.239","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:06:26.204Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"yahoo-yahooaudioconf-activex-bo(33408)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33408"},{"name":"23291","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23291"},{"name":"24742","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24742"},{"name":"VU#388377","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/388377"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-07-012.html"},{"name":"2523","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/2523"},{"name":"ADV-2007-1219","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1219"},{"name":"34319","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/34319"},{"name":"1017867","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1017867"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://messenger.yahoo.com/security_update.php?id=031207"},{"name":"20070403 ZDI-07-012: Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/464607/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-04-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"yahoo-yahooaudioconf-activex-bo(33408)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33408"},{"name":"23291","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23291"},{"name":"24742","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24742"},{"name":"VU#388377","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/388377"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-07-012.html"},{"name":"2523","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/2523"},{"name":"ADV-2007-1219","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1219"},{"name":"34319","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/34319"},{"name":"1017867","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1017867"},{"tags":["x_refsource_CONFIRM"],"url":"http://messenger.yahoo.com/security_update.php?id=031207"},{"name":"20070403 ZDI-07-012: Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/464607/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1680","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"yahoo-yahooaudioconf-activex-bo(33408)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/33408"},{"name":"23291","refsource":"BID","url":"http://www.securityfocus.com/bid/23291"},{"name":"24742","refsource":"SECUNIA","url":"http://secunia.com/advisories/24742"},{"name":"VU#388377","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/388377"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-07-012.html","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-07-012.html"},{"name":"2523","refsource":"SREASON","url":"http://securityreason.com/securityalert/2523"},{"name":"ADV-2007-1219","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1219"},{"name":"34319","refsource":"OSVDB","url":"http://osvdb.org/34319"},{"name":"1017867","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1017867"},{"name":"http://messenger.yahoo.com/security_update.php?id=031207","refsource":"CONFIRM","url":"http://messenger.yahoo.com/security_update.php?id=031207"},{"name":"20070403 ZDI-07-012: Yahoo! Messenger AudioConf ActiveX Control Buffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/464607/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1680","datePublished":"2007-04-06T01:00:00.000Z","dateReserved":"2007-03-26T00:00:00.000Z","dateUpdated":"2024-08-07T13:06:26.204Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-04-06 01:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:messenger:8.0:*:*:*:*:*:*:*","matchCriteriaId":"B7178A56-42F9-44BC-8742-402480F761FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:messenger:8.0.0.863:*:*:*:*:*:*:*","matchCriteriaId":"5D369102-AC28-45D1-A9E7-B6C4F34529C1"},{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:messenger:8.0_2005.1.1.4:*:*:*:*:*:*:*","matchCriteriaId":"7B4212E3-8338-430F-A9BC-A28D502B8B81"},{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:messenger:8.1.0.209:*:*:*:*:*:*:*","matchCriteriaId":"7A9243F4-ADE8-4B7A-A195-EEAD41FF14EA"},{"vulnerable":true,"criteria":"cpe:2.3:a:yahoo:messenger:8.1.0.239:*:*:*:*:*:*:*","matchCriteriaId":"3CAF169E-8466-43EF-A03D-D49256EB2C18"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1680","Ordinal":"1","Title":"CVE-2007-1680","CVE":"CVE-2007-1680","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1680","Ordinal":"1","NoteData":"Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.","Type":"Description","Title":"CVE-2007-1680"},{"CveYear":"2007","CveId":"1680","Ordinal":"2","NoteData":"2007-04-05","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1680","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}