7.8

CVE-2007-0612

Exploit
Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 5.0_ta3
Microsoft ≫ Ie Version 6.0 Update sp1
Microsoft ≫ Ie Version 7.0 Edition vista
Microsoft ≫ Internet Explorer Version 5.0.1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp1
Microsoft ≫ Internet Explorer Version 5.0.1 Update sp4
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 7.0 Update beta1
Microsoft ≫ Internet Explorer Version 7.0 Update beta2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 42.88% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html
http://osvdb.org/32628
http://securityreason.com/securityalert/2199
http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html
http://www.securityfocus.com/archive/1/458443/100/0/threaded
http://www.securityfocus.com/bid/22288
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/31867