CVE-2007-2222
high · 9.3Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.
9.3
CVSS
54.7%
EPSS (exploit prob.)
99th
EPSS percentile
2007-06-12
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_2000 | all versions |
| microsoft | internet_explorer | 5.01 |
| microsoft | internet_explorer | 6 |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_2003_server | sp2 |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 7.0 |
| microsoft | windows_2003_server | all versions |
| microsoft | windows_2003_server | all versions |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_2003_server | sp2 |
| microsoft | internet_explorer | 6 |
| microsoft | internet_explorer | 7.0 |
| microsoft | windows_vista | all versions |
| microsoft | windows_vista | all versions |
| microsoft | internet_explorer | 7.0 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/35353
- http://retrogod.altervista.org/win_speech_2k_sp4.html
- http://retrogod.altervista.org/win_speech_xp_sp2.html
- http://secunia.com/advisories/25627
- http://securitytracker.com/id?1018235
- http://www.exploit-db.com/exploits/4065
- http://www.kb.cert.org/vuls/id/507433
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/bid/24426
- http://www.us-cert.gov/cas/techalerts/TA07-163A.html
- http://www.vupen.com/english/advisories/2007/2153
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34630
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2031
- http://osvdb.org/35353
- http://retrogod.altervista.org/win_speech_2k_sp4.html
- http://retrogod.altervista.org/win_speech_xp_sp2.html
- http://secunia.com/advisories/25627
- http://securitytracker.com/id?1018235
- http://www.exploit-db.com/exploits/4065
- http://www.kb.cert.org/vuls/id/507433
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/bid/24426
- http://www.us-cert.gov/cas/techalerts/TA07-163A.html
- http://www.vupen.com/english/advisories/2007/2153
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-2222