Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-3902 | First vendor Publication | 2007-12-11 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3902 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
50 % | CWE-399 | Resource Management Errors |
50 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:4582 | |||
Oval ID: | oval:org.mitre.oval:def:4582 | ||
Title: | Uninitialized Memory Corruption Vulnerability | ||
Description: | Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2007-3902 | Version: | 5 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista | Product(s): | Microsoft Internet Explorer |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2007-12-31 | Vantage Linguistics AnswerWorks 4 API ActiveX Control BoF Exploit |
OpenVAS Exploits
Date | Description |
---|---|
2011-01-14 | Name : Microsoft Internet Explorer mshtml.dll Remote Memory Corruption Vulnerability... File : nvt/gb_ms07-069.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
39118 | Microsoft IE Object setExpression Function Memory Corruption Internet Explorer contains a flaw that may allow a malicious user to execute arbitrary code. The issue is triggered when theCRecalcProperty function in mshtml.dll references memory that has already been freed. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | MSN Heartbeat ActiveX clsid access RuleID : 4167 - Revision : 16 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Internet Explorer object reference memory corruption attempt RuleID : 17622 - Revision : 11 - Type : BROWSER-IE |
2014-01-10 | Microsoft Internet Explorer location.replace memory corruption attempt RuleID : 16065 - Revision : 11 - Type : BROWSER-IE |
2014-01-10 | Intuit QuickBooks Online Import 5 ActiveX clsid unicode access RuleID : 12970 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Import 5 ActiveX clsid access RuleID : 12969 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Import 4 ActiveX clsid unicode access RuleID : 12968 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Import 4 ActiveX clsid access RuleID : 12967 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Import 3 ActiveX clsid unicode access RuleID : 12966 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Import 3 ActiveX clsid access RuleID : 12965 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Import 2 ActiveX clsid unicode access RuleID : 12964 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Import 2 ActiveX clsid access RuleID : 12963 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Import 1 ActiveX clsid unicode access RuleID : 12962 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Import 1 ActiveX clsid access RuleID : 12961 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | MSN Heartbeat 3 ActiveX clsid unicode access RuleID : 12960 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer MSN Heartbeat 3 ActiveX clsid access RuleID : 12959 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | MSN Heartbeat 2 ActiveX clsid unicode access RuleID : 12958 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer MSN Heartbeat 2 ActiveX clsid access RuleID : 12957 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | MSN Heartbeat ActiveX clsid unicode access RuleID : 12956 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | DXLTPI.DLL ActiveX clsid unicode access RuleID : 12955 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Internet Explorer DXLTPI.DLL ActiveX clsid access RuleID : 12954 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Vantage Linguistics 3 ActiveX clsid unicode access RuleID : 12953 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Vantage Linguistics 3 ActiveX clsid access RuleID : 12952 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Vantage Linguistics 2 ActiveX clsid unicode access RuleID : 12951 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Vantage Linguistics 2 ActiveX clsid access RuleID : 12950 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Vantage Linguistics 1 ActiveX clsid unicode access RuleID : 12949 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Vantage Linguistics 1 ActiveX clsid access RuleID : 12948 - Revision : 11 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 10 ActiveX clsid unicode access RuleID : 12412 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 10 ActiveX clsid access RuleID : 12411 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 9 ActiveX clsid unicode access RuleID : 12410 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 9 ActiveX clsid access RuleID : 12409 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 8 ActiveX clsid unicode access RuleID : 12408 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 8 ActiveX clsid access RuleID : 12407 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 7 ActiveX clsid unicode access RuleID : 12406 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 7 ActiveX clsid access RuleID : 12405 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 6 ActiveX clsid unicode access RuleID : 12404 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 6 ActiveX clsid access RuleID : 12403 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 5 ActiveX clsid unicode access RuleID : 12402 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 5 ActiveX clsid access RuleID : 12401 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 4 ActiveX clsid unicode access RuleID : 12400 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 4 ActiveX clsid access RuleID : 12399 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 3 ActiveX clsid unicode access RuleID : 12398 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 3 ActiveX clsid access RuleID : 12397 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 2 ActiveX clsid unicode access RuleID : 12396 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 2 ActiveX clsid access RuleID : 12395 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Intuit QuickBooks Online Edition 1 ActiveX clsid unicode access RuleID : 12394 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Intuit QuickBooks Online Edition 1 ActiveX clsid access RuleID : 12393 - Revision : 12 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-12-11 | Name : Arbitrary code can be executed on the remote host through the web client. File : smb_nt_ms07-069.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:15:38 |
|
2024-11-28 12:12:59 |
|
2021-07-27 00:24:34 |
|
2021-07-24 01:44:11 |
|
2021-07-24 01:04:00 |
|
2021-07-23 21:25:01 |
|
2021-07-23 17:24:38 |
|
2021-07-23 01:44:02 |
|
2021-07-23 01:04:01 |
|
2021-07-22 21:24:58 |
|
2021-05-04 12:06:09 |
|
2021-04-22 01:06:42 |
|
2020-05-23 00:20:09 |
|
2019-03-19 12:02:30 |
|
2018-10-16 00:19:11 |
|
2018-10-13 00:22:37 |
|
2017-11-09 12:02:25 |
|
2017-09-29 09:23:09 |
|
2017-07-29 12:02:24 |
|
2016-04-26 16:23:42 |
|
2014-02-17 10:41:01 |
|
2014-01-19 21:24:20 |
|
2013-05-11 10:32:19 |
|