7.5
CVE-2007-3892
- EPSS 40.82%
- Veröffentlicht 09.10.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version5.00.2516.1900
Microsoft ≫ Internet Explorer Version5.00.2614.3500
Microsoft ≫ Internet Explorer Version5.00.2919.800
Microsoft ≫ Internet Explorer Version5.00.2919.3800
Microsoft ≫ Internet Explorer Version5.00.2919.6307
Microsoft ≫ Internet Explorer Version5.00.2920.0000
Microsoft ≫ Internet Explorer Version5.00.3103.1000
Microsoft ≫ Internet Explorer Version5.00.3105.0106
Microsoft ≫ Internet Explorer Version5.00.3314.2101
Microsoft ≫ Internet Explorer Version5.00.3315.1000
Microsoft ≫ Internet Explorer Version5.00.3502.1000
Microsoft ≫ Internet Explorer Version5.00.3700.1000
Microsoft ≫ Internet Explorer Version6.00.2462.0000
Microsoft ≫ Internet Explorer Version6.00.2479.0006
Microsoft ≫ Internet Explorer Version6.00.2600.0000
Microsoft ≫ Internet Explorer Version6.00.2800.1106
Microsoft ≫ Internet Explorer Version6.00.2900.2180
Microsoft ≫ Internet Explorer Version6.00.3663.0000
Microsoft ≫ Internet Explorer Version6.00.3718.0000
Microsoft ≫ Internet Explorer Version6.00.3790.0000
Microsoft ≫ Internet Explorer Version6.00.3790.1830
Microsoft ≫ Internet Explorer Version6.00.3790.3959
Microsoft ≫ Internet Explorer Version7.0
Microsoft ≫ Internet Explorer Version7.0 Updatebeta1
Microsoft ≫ Internet Explorer Version7.0 Updatebeta2
Microsoft ≫ Internet Explorer Version7.0 Updatebeta3
Microsoft ≫ Internet Explorer Version7.00.5730.1100
Microsoft ≫ Internet Explorer Version7.00.6000.16386
Microsoft ≫ Internet Explorer Version7.00.6000.16441
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 40.82% | 0.97 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.