"Yahoo! Chat Add Buddy Without Consent Privacy Issue
Services affected: ALL of Yahoo! Chat
Description: A vulnerability exists in Yahoo!'s Chat servers that allows for chatters to be added to your friends list completely without their knowledge or permissionof the operation. As a result private status messages can be read and online Yahoo! Chat activity can be monitored stealthily."
Security Focus BUGTRAQ here.
And another....
"Yahoo! Messenger URL Handler Remote DoS Vulnerability
Application affected: Yahoo! Messenger ver. 5.x - 6.0 Windows (all builds), *Nix/Mac ? (not tested)
Description: A Denial-of-Service attack can be launched against Yahoo! Messenger which can be exploited both locally and remotely through IFRAMEs or by tricking the target into clicking on a YMSGR: URL handler link when in chat or in pm. A remote user can disconnect Yahoo! Messenger users via e-mail or by having the victim visit a web page."
Security Focus BUGTRAQ here.

Services affected: ALL of Yahoo! Chat
Description: A vulnerability exists in Yahoo!'s Chat servers that allows for chatters to be added to your friends list completely without their knowledge or permissionof the operation. As a result private status messages can be read and online Yahoo! Chat activity can be monitored stealthily."
Security Focus BUGTRAQ here.
And another....
"Yahoo! Messenger URL Handler Remote DoS Vulnerability
Application affected: Yahoo! Messenger ver. 5.x - 6.0 Windows (all builds), *Nix/Mac ? (not tested)
Description: A Denial-of-Service attack can be launched against Yahoo! Messenger which can be exploited both locally and remotely through IFRAMEs or by tricking the target into clicking on a YMSGR: URL handler link when in chat or in pm. A remote user can disconnect Yahoo! Messenger users via e-mail or by having the victim visit a web page."
Security Focus BUGTRAQ here.