CVE-2012-0268

medium
Published 2012-01-19 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.1

Description

Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
yahoomessenger{"endIncluding":"11.5.0.152"}
yahoomessenger0.99.17-1
yahoomessenger1.0
yahoomessenger1.0.4
yahoomessenger1.0.6
yahoomessenger2.0.1.4
yahoomessenger3.0
yahoomessenger3.0.1
yahoomessenger3.5
yahoomessenger4.0
yahoomessenger4.1
yahoomessenger5.0
yahoomessenger5.0.1046
yahoomessenger5.0.1065
yahoomessenger5.0.1232
yahoomessenger5.5
yahoomessenger5.5.1249
yahoomessenger5.6
yahoomessenger5.6.0.1347
yahoomessenger5.6.0.1351
yahoomessenger5.6.0.1355
yahoomessenger5.6.0.1356
yahoomessenger5.6.0.1358
yahoomessenger6.0
yahoomessenger6.0.0.1643
yahoomessenger6.0.0.1750
yahoomessenger6.0.0.1921
yahoomessenger6.1
yahoomessenger7.0
yahoomessenger7.0.0.426
yahoomessenger7.0.0.437
yahoomessenger7.0.438
yahoomessenger7.5
yahoomessenger7.5.0.814
yahoomessenger8.0
yahoomessenger8.0.0.505
yahoomessenger8.0.0.508
yahoomessenger8.0.0.701
yahoomessenger8.0.0.716
yahoomessenger8.0.0.863
yahoomessenger8.0.1
yahoomessenger8.0_2005.1.1.4
yahoomessenger8.1
yahoomessenger8.1.0.195
yahoomessenger8.1.0.209
yahoomessenger8.1.0.239
yahoomessenger8.1.0.244
yahoomessenger8.1.0.249
yahoomessenger8.1.0.401
yahoomessenger8.1.0.402
yahoomessenger8.1.0.413
yahoomessenger8.1.0.416
yahoomessenger8.1.0.419
yahoomessenger8.1.0.421
yahoomessenger9.0.0.797
yahoomessenger9.0.0.907
yahoomessenger9.0.0.922
yahoomessenger9.0.0.1389
yahoomessenger9.0.0.1912
yahoomessenger9.0.0.2018
yahoomessenger9.0.0.2034
yahoomessenger9.0.0.2112
yahoomessenger9.0.0.2123
yahoomessenger9.0.0.2128
yahoomessenger9.0.0.2133
yahoomessenger9.0.0.2136
yahoomessenger9.0.0.2152
yahoomessenger9.0.0.2160
yahoomessenger9.0.0.2161
yahoomessenger9.0.0.2162
yahoomessenger10.0.0.331
yahoomessenger10.0.0.525
yahoomessenger10.0.0.542
yahoomessenger10.0.0.1102
yahoomessenger10.0.0.1241
yahoomessenger10.0.0.1258
yahoomessenger10.0.0.1264
yahoomessenger10.0.0.1267
yahoomessenger10.0.0.1270
yahoomessenger11.0.0.1751
yahoomessenger11.0.0.2009
yahoomessenger11.0.0.2014

References

CWEs

CWE-189

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.