← All CVEs

CVE-2007-0944

high · 9.3

Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; and 6 on Windows XP SP2, or Windows Server 2003 SP1 or SP2 allows remote attackers to execute arbitrary code by calling deleteCell on a named table row in a named table column, then accessing the column, which causes Internet Explorer to access previously deleted objects, aka the "Uninitialized Memory Corruption Vulnerability."

9.3
CVSS
35.1%
EPSS (exploit prob.)
98th
EPSS percentile
2007-05-08
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftinternet_explorer5.01
microsoftwindows_2000all versions
microsoftie6.0
microsoftwindows_xpall versions
microsoftie6.0
microsoftwindows_2003_serversp2
microsoftie6.0
microsoftwindows_2003_serversp1
microsoftie6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0944