CVE-2014-7216: Yahoo Messenger

High severity, CVSS 9.3. EPSS: 6.8% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut or (2) title keys in an emoticons.xml file.

Affected products

  • Yahoo Messenger: up to and including 11.5.0.228

Published 2015-09-11. Last modified 2026-06-17.