Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-2222
Description:Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-2222
BugTraq ID: 24426
http://www.securityfocus.com/bid/24426
Cert/CC Advisory: TA07-163A
http://www.us-cert.gov/cas/techalerts/TA07-163A.html
CERT/CC vulnerability note: VU#507433
http://www.kb.cert.org/vuls/id/507433
http://www.exploit-db.com/exploits/4065
HPdes Security Advisory: HPSBST02231
http://www.securityfocus.com/archive/1/471947/100/0/threaded
HPdes Security Advisory: SSRT071438
http://www.securityfocus.com/archive/1/471947/100/0/threaded
http://retrogod.altervista.org/win_speech_2k_sp4.html
http://retrogod.altervista.org/win_speech_xp_sp2.html
Microsoft Security Bulletin: MS07-033
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033
http://osvdb.org/35353
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2031
http://securitytracker.com/id?1018235
http://secunia.com/advisories/25627
http://www.vupen.com/english/advisories/2007/2153
XForce ISS Database: ie-speech-code-execution(34630)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34630




© 1998-2025 E-Soft Inc. All rights reserved.