7.1

CVE-2007-5133

Exploit
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2003 Server Edition itanium
Microsoft ≫ Windows 2003 Server Edition std
Microsoft ≫ Windows 2003 Server Edition wed
Microsoft ≫ Windows 2003 Server Edition x64
Microsoft ≫ Windows 2003 Server Edition x64-std
Microsoft ≫ Windows 2003 Server Edition xp-64bit
Microsoft ≫ Windows 2003 Server Update gold
Microsoft ≫ Windows 2003 Server Update gold Edition itanium
Microsoft ≫ Windows 2003 Server Update gold Edition std
Microsoft ≫ Windows 2003 Server Update gold Edition wed
Microsoft ≫ Windows 2003 Server Update gold Edition x64
Microsoft ≫ Windows 2003 Server Update gold Edition x64-std
Microsoft ≫ Windows 2003 Server Update r2 Edition std
Microsoft ≫ Windows 2003 Server Update r2 Edition wed
Microsoft ≫ Windows 2003 Server Update r2 Edition x64
Microsoft ≫ Windows 2003 Server Update r2 Edition x64-std
Microsoft ≫ Windows 2003 Server Update sp1 Edition std
Microsoft ≫ Windows 2003 Server Update sp1 Edition wed
Microsoft ≫ Windows 2003 Server Update sp2 Edition itanium
Microsoft ≫ Windows 2003 Server Update sp2 Edition std
Microsoft ≫ Windows 2003 Server Update sp2 Edition wed
Microsoft ≫ Windows 2003 Server Update sp2 Edition x64
Microsoft ≫ Windows Vista Edition business
Microsoft ≫ Windows Vista Edition enterprise
Microsoft ≫ Windows Vista Edition home_basic
Microsoft ≫ Windows Vista Edition home_premium
Microsoft ≫ Windows Vista Edition starter
Microsoft ≫ Windows Vista Edition ultimate
Microsoft ≫ Windows Vista Edition x64
Microsoft ≫ Windows Vista Edition x64-business
Microsoft ≫ Windows Vista Edition x64-home_basic
Microsoft ≫ Windows Vista Update gold
Microsoft ≫ Windows Vista Update gold Edition x64
Microsoft ≫ Windows Vista Version -
Microsoft ≫ Windows Xp Edition 64bit
Microsoft ≫ Windows Xp Edition embedded
Microsoft ≫ Windows Xp Edition ibm_oem
Microsoft ≫ Windows Xp Edition media_center
Microsoft ≫ Windows Xp Edition pro
Microsoft ≫ Windows Xp Edition tablet_pc
Microsoft ≫ Windows Xp Edition x64
Microsoft ≫ Windows Xp Update gold
Microsoft ≫ Windows Xp Update gold Edition embedded
Microsoft ≫ Windows Xp Update gold Edition media_center
Microsoft ≫ Windows Xp Update gold Edition pro
Microsoft ≫ Windows Xp Update gold Edition tablet_pc
Microsoft ≫ Windows Xp Update sp1
Microsoft ≫ Windows Xp Update sp1 Edition 64bit
Microsoft ≫ Windows Xp Update sp1 Edition embedded
Microsoft ≫ Windows Xp Update sp1 Edition ibm_oem
Microsoft ≫ Windows Xp Update sp1 Edition media_center
Microsoft ≫ Windows Xp Update sp1 Edition pro
Microsoft ≫ Windows Xp Update sp1 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp2 Edition embedded
Microsoft ≫ Windows Xp Update sp2 Edition media_center
Microsoft ≫ Windows Xp Update sp2 Edition pro
Microsoft ≫ Windows Xp Update sp2 Edition tablet_pc
Microsoft ≫ Windows Xp Update sp2 Edition x64
Microsoft ≫ Windows Xp Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 22.91% 0.974
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/45521
http://www.securityfocus.com/archive/1/480594/100/0/threaded
http://www.securityfocus.com/archive/1/480706/100/0/threaded
http://www.securityfocus.com/archive/1/480827/100/0/threaded
http://www.securityfocus.com/archive/1/480854/100/0/threaded
http://www.securityfocus.com/archive/1/480864/100/0/threaded
http://www.securityfocus.com/bid/25816
Exploit