← All CVEs

CVE-2007-0612

high · 7.8

Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.

7.8
CVSS
43.9%
EPSS (exploit prob.)
99th
EPSS percentile
2007-01-31
Published

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

VendorProductAffected versions
microsoftie5.0_ta3
microsoftie6.0
microsoftie7.0
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.0.1
microsoftinternet_explorer5.5
microsoftinternet_explorer6.0
microsoftinternet_explorer7.0
microsoftinternet_explorer7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0612