Vulnerabilities > CVE-2007-0371 - Denial of Service vulnerability in BrowseDialog ActiveX Control CCRPBDS6.DLL

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
common-controls-replacement-project
exploit available

Summary

A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.

Vulnerable Configurations

Part Description Count
Application
Common_Controls_Replacement_Project
1

Exploit-Db

descriptionBrowseDialog Class (ccrpbds6.dll) Internet Explorer Denial of Service. CVE-2007-0371. Dos exploit for windows platform
fileexploits/windows/dos/3155.html
idEDB-ID:3155
last seen2016-01-31
modified2007-01-18
platformwindows
port
published2007-01-18
reportershinnai
sourcehttps://www.exploit-db.com/download/3155/
titleBrowseDialog Class ccrpbds6.dll Internet Explorer 7 - Denial of Service
typedos