There is no reason for a Flash file on an ad network to be permitted to use any functions other than those necessary for basic animation, mouse/touch interaction handlers, and a navigateToURL call. The same principle applies to custom HTML/JS. Otherwise the advertiser might as well toss a bitcoin miner into their scripts; it's not like Yahoo is stopping them.
By not implementing the bare minimum of incredibly obvious basic precautions for handling mysterious executable content before spraying it indiscriminately across the entire web, Yahoo's incompetence borders on malice and in my mind that makes them complicit in these crimes.