V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2007-0612
CVE
HighConfirmedExploit available

Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Exp…

CVSS
7.8
High
EPSS
0.54
p98
Published
2007-01-01
Updated
2007-01-01
Description

Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.

Affected products
IeInternet_explorer
CVSS vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Timeline
2007-01-01
Published
2007-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.539 · p98
Known exploited (KEV)
No
Known exploits — Сканер-ВС
29536
exploitdb · https://www.exploit-db.com/exploits/29536
Enterprise
Affected software
ProductVendorStatus
ie*Tracked
internet_explorer*Tracked
Source databases
CVE