← All CVEs

CVE-2007-0947

high · 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.

9.3
CVSS
32.0%
EPSS (exploit prob.)
98th
EPSS percentile
2007-05-08
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp2
microsoftwindows_vistaall versions
microsoftwindows_xpall versions
microsoftinternet_explorer6
microsoftinternet_explorer7.0
microsoftwindows_2003_serversp1
microsoftinternet_explorer6
microsoftinternet_explorer7.0
microsoftwindows_2003_serversp2
microsoftinternet_explorer6
microsoftinternet_explorer7.0
microsoftwindows_vistaall versions
microsoftinternet_explorer7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0947