7.1

CVE-2007-5133

Exploit

Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2003 Server Editionitanium
MicrosoftWindows 2003 Server Editionx64-std
MicrosoftWindows 2003 Server Editionxp-64bit
MicrosoftWindows 2003 Server Updategold Editionitanium
MicrosoftWindows 2003 Server Updategold Editionstd
MicrosoftWindows 2003 Server Updategold Editionwed
MicrosoftWindows 2003 Server Updategold Editionx64
MicrosoftWindows 2003 Server Updategold Editionx64-std
MicrosoftWindows 2003 Server Updater2 Editionstd
MicrosoftWindows 2003 Server Updater2 Editionwed
MicrosoftWindows 2003 Server Updater2 Editionx64
MicrosoftWindows 2003 Server Updater2 Editionx64-std
MicrosoftWindows 2003 Server Updatesp1 Editionstd
MicrosoftWindows 2003 Server Updatesp1 Editionwed
MicrosoftWindows 2003 Server Updatesp2 Editionitanium
MicrosoftWindows 2003 Server Updatesp2 Editionstd
MicrosoftWindows 2003 Server Updatesp2 Editionwed
MicrosoftWindows 2003 Server Updatesp2 Editionx64
MicrosoftWindows Vista Editionbusiness
MicrosoftWindows Vista Editionenterprise
MicrosoftWindows Vista Editionhome_basic
MicrosoftWindows Vista Editionhome_premium
MicrosoftWindows Vista Editionstarter
MicrosoftWindows Vista Editionultimate
MicrosoftWindows Vista Editionx64
MicrosoftWindows Vista Editionx64-business
MicrosoftWindows Vista Editionx64-home_basic
MicrosoftWindows Vista Updategold
MicrosoftWindows Vista Updategold Editionx64
MicrosoftWindows Vista Version-
MicrosoftWindows Xp Edition64bit
MicrosoftWindows Xp Editionembedded
MicrosoftWindows Xp Editionibm_oem
MicrosoftWindows Xp Editionmedia_center
MicrosoftWindows Xp Editionpro
MicrosoftWindows Xp Editiontablet_pc
MicrosoftWindows Xp Editionx64
MicrosoftWindows Xp Updategold
MicrosoftWindows Xp Updategold Editionembedded
MicrosoftWindows Xp Updategold Editionmedia_center
MicrosoftWindows Xp Updategold Editionpro
MicrosoftWindows Xp Updategold Editiontablet_pc
MicrosoftWindows Xp Updatesp1
MicrosoftWindows Xp Updatesp1 Edition64bit
MicrosoftWindows Xp Updatesp1 Editionembedded
MicrosoftWindows Xp Updatesp1 Editionibm_oem
MicrosoftWindows Xp Updatesp1 Editionmedia_center
MicrosoftWindows Xp Updatesp1 Editionpro
MicrosoftWindows Xp Updatesp1 Editiontablet_pc
MicrosoftWindows Xp Updatesp2
MicrosoftWindows Xp Updatesp2 Editionembedded
MicrosoftWindows Xp Updatesp2 Editionmedia_center
MicrosoftWindows Xp Updatesp2 Editionpro
MicrosoftWindows Xp Updatesp2 Editiontablet_pc
MicrosoftWindows Xp Updatesp2 Editionx64
MicrosoftWindows Xp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 45.24% 0.975
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C