9.3

CVE-2007-6255

Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 2000 Version- Updatesp4
   MicrosoftInternet Explorer Version5.01 Updatesp4
   MicrosoftInternet Explorer Version6 Updatesp1
MicrosoftWindows Server 2003 Version- HwPlatformx64
   MicrosoftInternet Explorer Version6
MicrosoftWindows Server 2003 Version- Updatesp1
   MicrosoftInternet Explorer Version6
MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformitanium
   MicrosoftInternet Explorer Version6
MicrosoftWindows Server 2003 Version- Updatesp2
   MicrosoftInternet Explorer Version6
MicrosoftWindows Server 2003 Version- Updatesp2 HwPlatformitanium
   MicrosoftInternet Explorer Version6
MicrosoftWindows Server 2003 Version- Updatesp2 HwPlatformx64
   MicrosoftInternet Explorer Version6
MicrosoftWindows Xp Version- SwEditionprofessional HwPlatformx64
   MicrosoftInternet Explorer Version6
MicrosoftWindows Xp Version- Updatesp2
   MicrosoftInternet Explorer Version6
MicrosoftWindows Xp Version- Updatesp2 SwEditionprofessional HwPlatformx64
   MicrosoftInternet Explorer Version6
MicrosoftWindows Server 2003 Version- HwPlatformx64
   MicrosoftInternet Explorer Version7
MicrosoftWindows Server 2003 Version- Updatesp1
   MicrosoftInternet Explorer Version7
MicrosoftWindows Server 2003 Version- Updatesp1 HwPlatformitanium
   MicrosoftInternet Explorer Version7
MicrosoftWindows Server 2003 Version- Updatesp2
   MicrosoftInternet Explorer Version7
MicrosoftWindows Server 2003 Version- Updatesp2 HwPlatformitanium
   MicrosoftInternet Explorer Version7
MicrosoftWindows Server 2003 Version- Updatesp2 HwPlatformx64
   MicrosoftInternet Explorer Version7
MicrosoftWindows Vista Version-
   MicrosoftInternet Explorer Version7
MicrosoftWindows Vista Version- HwPlatformx64
   MicrosoftInternet Explorer Version7
MicrosoftWindows Xp Version- Editionprofessional HwPlatformx64
   MicrosoftInternet Explorer Version7
MicrosoftWindows Xp Version- Updatesp2
   MicrosoftInternet Explorer Version7
MicrosoftWindows Xp Version- Updatesp2 Editionprofessional HwPlatformx64
   MicrosoftInternet Explorer Version7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 57.95% 0.981
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.