CVE-2012-0268: Yahoo Messenger

Medium severity, CVSS 5.1. EPSS: 1.7% chance of exploitation in the next 30 days.

Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow.

Affected products

  • Yahoo Messenger: up to and including 11.5.0.152; version 0.99.17-1 only; version 1.0 only; version 1.0.4 only; version 1.0.6 only; version 2.0.1.4 only; …

Published 2012-01-19. Last modified 2026-06-16.