← All CVEs

CVE-2007-0099

high · 9.3

Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."

9.3
CVSS
25.1%
EPSS (exploit prob.)
98th
EPSS percentile
2007-01-08
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-362

Affected products

VendorProductAffected versions
microsoftxml_core_services3.0
microsoftinternet_explorer6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0099