Lucene search

K
cve[email protected]CVE-2007-2223
HistoryAug 14, 2007 - 9:17 p.m.

CVE-2007-2223

2007-08-1421:17:00
CWE-119
CWE-190
web.nvd.nist.gov
39
cve-2007-2223
nvd
microsoft
xml
core services
msxml
buffer overflow
integer overflow
remote code execution

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.919 High

EPSS

Percentile

98.9%

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

Affected configurations

NVD
Node
microsoftxml_core_servicesMatch3.0
OR
microsoftxml_core_servicesMatch4.0
OR
microsoftxml_core_servicesMatch6.0
AND
microsoftwindows_server_2003
OR
microsoftwindows_server_2003Match-sp1
OR
microsoftwindows_server_2003Match-sp1itanium
OR
microsoftwindows_server_2003Match-sp2
OR
microsoftwindows_vistaMatch-x64
OR
microsoftwindows_vistaMatch-x86
OR
microsoftwindows_vistaMatch-goldx64
OR
microsoftwindows_vistaMatch-sp1x64
OR
microsoftwindows_xpMatch-professionalx64
OR
microsoftwindows_xpMatch-sp2
OR
microsoftwindows_xpMatch-sp2professionalx64
OR
microsoftwindows_xpMatch-sp3
Node
microsoftxml_core_servicesMatch4.0
AND
microsoftwindows_server_2008Match-
OR
microsoftwindows_server_2008Match-itanium
Node
microsoftxml_core_servicesMatch5.0
AND
microsoftexpression_web
OR
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2007
OR
microsoftoffice_compatibility_packMatch2007
OR
microsoftoffice_groove_serverMatch2007
OR
microsoftoffice_sharepoint_server
OR
microsoftword_viewerMatch2003

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.919 High

EPSS

Percentile

98.9%