
CVE-2020-20093 – RTLO Injection URI Spoofing
https://notcve.org/view.php?id=CVE-2020-20093
23 Mar 2022 — The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. Facebook Messenger app para iOS versiones 227.0 y anteriores y Android versión 228.1.0.10.116 y la interfaz de usuario anterior, no representan apropiadamente los mensajes URI para el usuario, lo que resulta en una suplantación de URI por medio de mensajes especialmente diseñados RTLO injecti... • https://packetstorm.news/files/id/166448 •

CVE-2020-17476
https://notcve.org/view.php?id=CVE-2020-17476
10 Aug 2020 — Mibew Messenger before 3.2.7 allows XSS via a crafted user name. Mibew Messenger versiones anteriores a 3.2.7, permite un ataque de tipo XSS por medio de un nombre de usuario diseñado • https://github.com/Mibew/mibew/commit/84f5bca0a90b2fe470e35e9b5121548ccce0093c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2014-8688
https://notcve.org/view.php?id=CVE-2014-8688
14 Mar 2017 — An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file. Se ha descubierto un problema en Telegram Messenger 2.6 para iOS y 1.8.2 para Android. Los mensajes secretos del chat están disponibles en texto plano en memoria de proceso y un archivo .db. • https://blog.zimperium.com/telegram-hack • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-7216 – Yahoo! Messenger 11.5.0.228 Buffer Overflow
https://notcve.org/view.php?id=CVE-2014-7216
04 Sep 2015 — Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file. Múltiples desbordamientos de buffer basado en pila en Yahoo! Messenger 11.5.0.228 y versiones anteriores, permite a atacantes remotos causar una denegación de servicio (colapso) y posiblemente ejecutar código arbitrario a través del (1) acceso directo o de (2) las clave... • http://packetstormsecurity.com/files/133443/Yahoo-Messenger-11.5.0.228-Buffer-Overflow.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2012-0268
https://notcve.org/view.php?id=CVE-2012-0268
19 Jan 2012 — Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow. Un desbordamiento de entero en el método CYImage::LoadJPG en YImage.dll en Yahoo! Messenger antes de v11.5.0.155, cuando la compartición fotos está activada, podría permitir a atacantes remotos ejecutar código de su elección a través de una imagen JPG modif... • http://secunia.com/advisories/47041 • CWE-189: Numeric Errors •

CVE-2007-4515 – Yahoo! Messenger - 'YVerInfo.dll' ActiveX Control Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-4515
31 Aug 2007 — Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information. Un desbordamiento de búfer en cierto control ActiveX en YVerInfo.dll versiones anteriores a 2007.8.27.1 en la conjunto de servicios para Yahoo! • https://www.exploit-db.com/exploits/16522 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-3147 – Yahoo! Messenger 8.1.0.249 - ActiveX Control Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-3147
11 Jun 2007 — Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party information. Desbordamiento de búfer en el control Yahoo! • https://www.exploit-db.com/exploits/16519 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-3148 – Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-2007-3148
11 Jun 2007 — Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method. El desbordamiento del búfer en el control ActiveX de Yahoo! Webcam Viewer en ywcvwr.dll versión 2.0.1.4 para Yahoo! • https://www.exploit-db.com/exploits/4043 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-0768 – Yahoo! Messenger 8.0 - Notification Message HTML Injection
https://notcve.org/view.php?id=CVE-2007-0768
06 Feb 2007 — Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information. Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en la funcionalidad Detalles de ... • https://www.exploit-db.com/exploits/29531 •

CVE-2006-6603
https://notcve.org/view.php?id=CVE-2006-6603
15 Dec 2006 — Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document. NOTE: some details were obtained from third party information. Desbordamiento de búfer en el controlador YMMAPI.YMailAttach ActiveX (ymmapi.dll) anterior a 2005.1.1.4 en Yahoo! Messenger permote a un atacante remoto ejecutar código de su elección a través de un documento HTML manipulado. • http://messenger.yahoo.com/security_update.php?id=120806 •