Vulnerabilities > CVE-2007-0612 - Unspecified vulnerability in Microsoft IE and Internet Explorer

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
microsoft
exploit available

Summary

Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.

Exploit-Db

descriptionMicrosoft Internet Explorer 5.0.1 Multiple ActiveX Controls Denial of Service Vulnerabilities. CVE-2007-0612. Dos exploit for windows platform
idEDB-ID:29536
last seen2016-02-03
modified2007-01-29
published2007-01-29
reporterAlexander Sotirov
sourcehttps://www.exploit-db.com/download/29536/
titleMicrosoft Internet Explorer 5.0.1 - Multiple ActiveX Controls Denial of Service Vulnerabilities