9.3

CVE-2007-3902

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Ie Version 5.x
Microsoft ≫ Ie Version 6.0 Update sp1
Microsoft ≫ Ie Version 6.0 Update sp2
Microsoft ≫ Internet Explorer Version 5.01
Microsoft ≫ Internet Explorer Version 5.1
Microsoft ≫ Internet Explorer Version 5.01 Update sp1
Microsoft ≫ Internet Explorer Version 5.01 Update sp2
Microsoft ≫ Internet Explorer Version 5.01 Update sp3
Microsoft ≫ Internet Explorer Version 5.01 Update sp4
Microsoft ≫ Internet Explorer Version 5.2.3
Microsoft ≫ Internet Explorer Version 5.5
Microsoft ≫ Internet Explorer Version 5.5 Update preview
Microsoft ≫ Internet Explorer Version 5.5 Update sp1
Microsoft ≫ Internet Explorer Version 5.5 Update sp2
Microsoft ≫ Internet Explorer Version 6 Update sp1
Microsoft ≫ Internet Explorer Version 6.0
Microsoft ≫ Internet Explorer Version 6.0.2600
Microsoft ≫ Internet Explorer Version 6.0.2800
Microsoft ≫ Internet Explorer Version 6.0.2800.1106
Microsoft ≫ Internet Explorer Version 6.0.2900
Microsoft ≫ Internet Explorer Version 6.0.2900.2180
Microsoft ≫ Internet Explorer Version 7.0
Microsoft ≫ Internet Explorer Version 7.0 Update beta
Microsoft ≫ Internet Explorer Version 7.0 Update beta1
Microsoft ≫ Internet Explorer Version 7.0 Update beta2
Microsoft ≫ Internet Explorer Version 7.0 Update beta3
Microsoft ≫ Internet Explorer Version 7.0.5730.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.51% 0.982
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/archive/1/485268/100/0/threaded
http://www.us-cert.gov/cas/techalerts/TA07-345A.html
US Government Resource
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=631
http://secunia.com/advisories/28036
Vendor Advisory
http://securitytracker.com/id?1019078
http://www.securityfocus.com/archive/1/484887/100/0/threaded
http://www.securityfocus.com/bid/26506
http://www.vupen.com/english/advisories/2007/4184
Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-073.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069
https://exchange.xforce.ibmcloud.com/vulnerabilities/38713
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4582