← All CVEs

CVE-2007-2222

high · 9.3

Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.

9.3
CVSS
54.7%
EPSS (exploit prob.)
99th
EPSS percentile
2007-06-12
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftinternet_explorer5.01
microsoftinternet_explorer6
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp2
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftinternet_explorer6
microsoftinternet_explorer7.0
microsoftwindows_2003_serverall versions
microsoftwindows_2003_serverall versions
microsoftwindows_2003_serversp1
microsoftwindows_2003_serversp2
microsoftinternet_explorer6
microsoftinternet_explorer7.0
microsoftwindows_vistaall versions
microsoftwindows_vistaall versions
microsoftinternet_explorer7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2222