9.3

CVE-2007-6255

Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Version - Update sp4
   Microsoft ≫ Internet Explorer Version 5.01 Update sp4
   Microsoft ≫ Internet Explorer Version 6 Update sp1
Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Version - Update sp1 HwPlatform itanium
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform itanium
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform x64
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Xp Version - SwEdition professional HwPlatform x64
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Xp Version - Update sp2 SwEdition professional HwPlatform x64
   Microsoft ≫ Internet Explorer Version 6
Microsoft ≫ Windows Server 2003 Version - HwPlatform x64
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Server 2003 Version - Update sp1
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Server 2003 Version - Update sp1 HwPlatform itanium
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Server 2003 Version - Update sp2
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform itanium
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Server 2003 Version - Update sp2 HwPlatform x64
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Vista Version -
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Vista Version - HwPlatform x64
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Xp Version - Edition professional HwPlatform x64
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Xp Version - Update sp2
   Microsoft ≫ Internet Explorer Version 7
Microsoft ≫ Windows Xp Version - Update sp2 Edition professional HwPlatform x64
   Microsoft ≫ Internet Explorer Version 7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 30.08% 0.98
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069
http://osvdb.org/44652
Broken Link
http://www.kb.cert.org/vuls/id/570089
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/28882
Third Party Advisory
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41940
Third Party Advisory
VDB Entry