9.3

CVE-2007-2223

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Xml Core Services Version 3.0
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Windows Server 2003 Version - Update sp1 HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Edition x64
   Microsoft ≫ Windows Vista Version - Edition x86
   Microsoft ≫ Windows Vista Version - Update gold HwPlatform x64
   Microsoft ≫ Windows Vista Version - Update sp1 HwPlatform x64
   Microsoft ≫ Windows Xp Version - SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Xml Core Services Version 4.0
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Windows Server 2003 Version - Update sp1 HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Edition x64
   Microsoft ≫ Windows Vista Version - Edition x86
   Microsoft ≫ Windows Vista Version - Update gold HwPlatform x64
   Microsoft ≫ Windows Vista Version - Update sp1 HwPlatform x64
   Microsoft ≫ Windows Xp Version - SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Xml Core Services Version 6.0
   Microsoft ≫ Windows Server 2003
   Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Windows Server 2003 Version - Update sp1 HwPlatform itanium
   Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Edition x64
   Microsoft ≫ Windows Vista Version - Edition x86
   Microsoft ≫ Windows Vista Version - Update gold HwPlatform x64
   Microsoft ≫ Windows Vista Version - Update sp1 HwPlatform x64
   Microsoft ≫ Windows Xp Version - SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Windows Xp Version - Update sp3
Microsoft ≫ Xml Core Services Version 4.0
   Microsoft ≫ Windows Server 2008 Version -
   Microsoft ≫ Windows Server 2008 Version - HwPlatform itanium
Microsoft ≫ Xml Core Services Version 5.0
   Microsoft ≫ Expression Web
   Microsoft ≫ Office Version 2003 Update sp2
   Microsoft ≫ Office Version 2007
   Microsoft ≫ Office Compatibility Pack Version 2007
   Microsoft ≫ Office Groove Server Version 2007
   Microsoft ≫ Office Sharepoint Server
   Microsoft ≫ Word Viewer Version 2003
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 48.72% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576
Broken Link
http://secunia.com/advisories/26447
Vendor Advisory
http://www.kb.cert.org/vuls/id/361968
Third Party Advisory
US Government Resource
http://www.securityfocus.com/archive/1/476527/100/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/archive/1/476747/100/0/threaded
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/25301
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1018559
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2007/2866
Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-048/
Third Party Advisory
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-042
Patch
Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2069
Third Party Advisory