9.3
CVE-2007-2223
- EPSS 68.2%
- Veröffentlicht 14.08.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Xml Core Services Version3.0
Microsoft ≫ Windows Server 2003
Microsoft ≫ Windows Server 2003 Version- Updatesp1
Microsoft ≫ Windows Server 2003 Version- Updatesp1 HwPlatformitanium
Microsoft ≫ Windows Server 2003 Version- Updatesp2
Microsoft ≫ Windows Vista Version- Editionx64
Microsoft ≫ Windows Vista Version- Editionx86
Microsoft ≫ Windows Vista Version- Updategold HwPlatformx64
Microsoft ≫ Windows Vista Version- Updatesp1 HwPlatformx64
Microsoft ≫ Windows Xp Version- SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp2
Microsoft ≫ Windows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp3
Microsoft ≫ Windows Server 2003 Version- Updatesp1
Microsoft ≫ Windows Server 2003 Version- Updatesp1 HwPlatformitanium
Microsoft ≫ Windows Server 2003 Version- Updatesp2
Microsoft ≫ Windows Vista Version- Editionx64
Microsoft ≫ Windows Vista Version- Editionx86
Microsoft ≫ Windows Vista Version- Updategold HwPlatformx64
Microsoft ≫ Windows Vista Version- Updatesp1 HwPlatformx64
Microsoft ≫ Windows Xp Version- SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp2
Microsoft ≫ Windows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp3
Microsoft ≫ Xml Core Services Version4.0
Microsoft ≫ Windows Server 2003
Microsoft ≫ Windows Server 2003 Version- Updatesp1
Microsoft ≫ Windows Server 2003 Version- Updatesp1 HwPlatformitanium
Microsoft ≫ Windows Server 2003 Version- Updatesp2
Microsoft ≫ Windows Vista Version- Editionx64
Microsoft ≫ Windows Vista Version- Editionx86
Microsoft ≫ Windows Vista Version- Updategold HwPlatformx64
Microsoft ≫ Windows Vista Version- Updatesp1 HwPlatformx64
Microsoft ≫ Windows Xp Version- SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp2
Microsoft ≫ Windows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp3
Microsoft ≫ Windows Server 2003 Version- Updatesp1
Microsoft ≫ Windows Server 2003 Version- Updatesp1 HwPlatformitanium
Microsoft ≫ Windows Server 2003 Version- Updatesp2
Microsoft ≫ Windows Vista Version- Editionx64
Microsoft ≫ Windows Vista Version- Editionx86
Microsoft ≫ Windows Vista Version- Updategold HwPlatformx64
Microsoft ≫ Windows Vista Version- Updatesp1 HwPlatformx64
Microsoft ≫ Windows Xp Version- SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp2
Microsoft ≫ Windows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp3
Microsoft ≫ Xml Core Services Version6.0
Microsoft ≫ Windows Server 2003
Microsoft ≫ Windows Server 2003 Version- Updatesp1
Microsoft ≫ Windows Server 2003 Version- Updatesp1 HwPlatformitanium
Microsoft ≫ Windows Server 2003 Version- Updatesp2
Microsoft ≫ Windows Vista Version- Editionx64
Microsoft ≫ Windows Vista Version- Editionx86
Microsoft ≫ Windows Vista Version- Updategold HwPlatformx64
Microsoft ≫ Windows Vista Version- Updatesp1 HwPlatformx64
Microsoft ≫ Windows Xp Version- SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp2
Microsoft ≫ Windows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp3
Microsoft ≫ Windows Server 2003 Version- Updatesp1
Microsoft ≫ Windows Server 2003 Version- Updatesp1 HwPlatformitanium
Microsoft ≫ Windows Server 2003 Version- Updatesp2
Microsoft ≫ Windows Vista Version- Editionx64
Microsoft ≫ Windows Vista Version- Editionx86
Microsoft ≫ Windows Vista Version- Updategold HwPlatformx64
Microsoft ≫ Windows Vista Version- Updatesp1 HwPlatformx64
Microsoft ≫ Windows Xp Version- SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp2
Microsoft ≫ Windows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
Microsoft ≫ Windows Xp Version- Updatesp3
Microsoft ≫ Xml Core Services Version4.0
Microsoft ≫ Xml Core Services Version5.0
Microsoft ≫ Expression Web
Microsoft ≫ Office Version2003 Updatesp2
Microsoft ≫ Office Version2007
Microsoft ≫ Office Compatibility Pack Version2007
Microsoft ≫ Office Groove Server Version2007
Microsoft ≫ Office Sharepoint Server
Microsoft ≫ Word Viewer Version2003
Microsoft ≫ Office Version2003 Updatesp2
Microsoft ≫ Office Version2007
Microsoft ≫ Office Compatibility Pack Version2007
Microsoft ≫ Office Groove Server Version2007
Microsoft ≫ Office Sharepoint Server
Microsoft ≫ Word Viewer Version2003
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 68.2% | 0.986 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-190 Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.