CVE-2007-3493
- EPSS 43.02%
- Published 29.06.2007 18:30:00
- Last modified 09.04.2025 00:30:58
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argum...
- EPSS 33.49%
- Published 29.06.2007 18:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length JavaScript variable.
- EPSS 18.76%
- Published 28.06.2007 18:30:00
- Last modified 09.04.2025 00:30:58
Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets t...
CVE-2007-3406
- EPSS 29.36%
- Published 26.06.2007 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or ...
CVE-2006-7206
- EPSS 48.54%
- Published 22.06.2007 00:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "i...
- EPSS 35.64%
- Published 21.06.2007 23:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.
CVE-2007-0218
- EPSS 55.15%
- Published 12.06.2007 19:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
CVE-2007-1750
- EPSS 65.91%
- Published 12.06.2007 19:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.
CVE-2007-1751
- EPSS 57.7%
- Published 12.06.2007 19:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corrupti...
CVE-2007-2222
- EPSS 67.29%
- Published 12.06.2007 19:30:00
- Last modified 09.04.2025 00:30:58
Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object tha...