Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-2225
Description:A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-2225
BugTraq ID: 24392
http://www.securityfocus.com/bid/24392
Bugtraq: 20070622 MS07-034: Executing arbitrary script with mhtml: protocol handler (Google Search)
http://www.securityfocus.com/archive/1/472002/100/0/threaded
Cert/CC Advisory: TA07-163A
http://www.us-cert.gov/cas/techalerts/TA07-163A.html
CERT/CC vulnerability note: VU#682825
http://www.kb.cert.org/vuls/id/682825
HPdes Security Advisory: HPSBST02231
http://www.securityfocus.com/archive/1/471947/100/0/threaded
HPdes Security Advisory: SSRT071438
http://www.securityfocus.com/archive/1/471947/100/0/threaded
http://archive.openmya.devnull.jp/2007.06/msg00060.html
http://openmya.hacker.jp/hasegawa/security/ms07-034.txt
Microsoft Security Bulletin: MS07-034
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034
http://osvdb.org/35345
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045
http://www.securitytracker.com/id?1018231
http://www.securitytracker.com/id?1018232
http://secunia.com/advisories/25639
http://www.vupen.com/english/advisories/2007/2154




© 1998-2025 E-Soft Inc. All rights reserved.