CVE-2007-2225
medium · 4.3A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability."
4.3
CVSS
25.0%
EPSS (exploit prob.)
98th
EPSS percentile
2007-06-12
Published
AV:N/AC:M/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows_2003_server | all versions |
| microsoft | windows_2003_server | all versions |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_2003_server | sp1 |
| microsoft | windows_2003_server | sp2 |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | windows_xp | all versions |
| microsoft | outlook_express | 6.0 |
| microsoft | windows_vista | all versions |
| microsoft | windows_vista | all versions |
| microsoft | windows_mail | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://archive.openmya.devnull.jp/2007.06/msg00060.html
- http://openmya.hacker.jp/hasegawa/security/ms07-034.txt
- http://osvdb.org/35345
- http://secunia.com/advisories/25639
- http://www.kb.cert.org/vuls/id/682825
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/archive/1/472002/100/0/threaded
- http://www.securityfocus.com/bid/24392
- http://www.securitytracker.com/id?1018231
- http://www.securitytracker.com/id?1018232
- http://www.us-cert.gov/cas/techalerts/TA07-163A.html
- http://www.vupen.com/english/advisories/2007/2154
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045
- http://archive.openmya.devnull.jp/2007.06/msg00060.html
- http://openmya.hacker.jp/hasegawa/security/ms07-034.txt
- http://osvdb.org/35345
- http://secunia.com/advisories/25639
- http://www.kb.cert.org/vuls/id/682825
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/archive/1/472002/100/0/threaded
- http://www.securityfocus.com/bid/24392
- http://www.securitytracker.com/id?1018231
- http://www.securitytracker.com/id?1018232
- http://www.us-cert.gov/cas/techalerts/TA07-163A.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-2225