Lucene search

K
cve[email protected]CVE-2007-0947
HistoryMay 08, 2007 - 11:19 p.m.

CVE-2007-0947

2007-05-0823:19:00
CWE-399
web.nvd.nist.gov
31
cve-2007-0947
microsoft
internet explorer
windows
vulnerability
remote code execution
html
memory corruption

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.938 High

EPSS

Percentile

99.1%

Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two “HTML Objects Memory Corruption Vulnerabilities” and a different issue than CVE-2007-0946.

Affected configurations

NVD
Node
microsoftwindows_2003_serverMatchsp1
OR
microsoftwindows_2003_serverMatchsp2
OR
microsoftwindows_vista
OR
microsoftwindows_xpsp2
AND
microsoftinternet_explorerMatch6
OR
microsoftinternet_explorerMatch7.0
Node
microsoftwindows_2003_serverMatchsp1
AND
microsoftinternet_explorerMatch6
OR
microsoftinternet_explorerMatch7.0
Node
microsoftwindows_2003_serverMatchsp2
AND
microsoftinternet_explorerMatch6
OR
microsoftinternet_explorerMatch7.0
Node
microsoftwindows_vista
AND
microsoftinternet_explorerMatch7.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.938 High

EPSS

Percentile

99.1%