4.6

CVE-2005-0242

Exploit
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yahoo ≫ Messenger Version 5.5
Yahoo ≫ Messenger Version 5.6
Yahoo ≫ Messenger Version 5.6.0.1351
Yahoo ≫ Messenger Version 6.0
Yahoo ≫ Messenger Version 6.0.0.1750
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.363
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://messenger.yahoo.com/security/update6.html
http://secunia.com/advisories/11815
Patch
http://secunia.com/secunia_research/2004-6/advisory/
Patch
Vendor Advisory
Exploit