|
|

CVE Reference: CVE-2007-1749 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2007-1749 |
|
|
Description: Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow. |
|
|
CVE Status: Candidate |
|
|
References: ST 1018568 SREASON http://securityreason.com/securityalert/3020 SAID Secunia Advisory: SA26409 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1784 MS http://www.microsoft.com/technet/security/bulletin/ms07-050.mspx MISC http://research.eeye.com/html/advisories/published/AD20070814a.html CERT-VN 468800 CERT http://www.us-cert.gov/cas/techalerts/TA07-226A.html BUGTRAQ http://www.securityfocus.com/archive/1/archive/1/476498/100/0/threaded BID 25310 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |