Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-3902
Description:Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-3902
BugTraq ID: 26506
http://www.securityfocus.com/bid/26506
Bugtraq: 20071211 ZDI-07-073: Microsoft Internet Explorer setExpression Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/484887/100/0/threaded
Cert/CC Advisory: TA07-345A
http://www.us-cert.gov/cas/techalerts/TA07-345A.html
HPdes Security Advisory: HPSBST02299
http://www.securityfocus.com/archive/1/485268/100/0/threaded
HPdes Security Advisory: SSRT071506
http://www.securityfocus.com/archive/1/485268/100/0/threaded
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=631
http://www.zerodayinitiative.com/advisories/ZDI-07-073.html
Microsoft Security Bulletin: MS07-069
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-069
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4582
http://securitytracker.com/id?1019078
http://secunia.com/advisories/28036
http://www.vupen.com/english/advisories/2007/4184
XForce ISS Database: ie-uninit-object-code-execution(38713)
https://exchange.xforce.ibmcloud.com/vulnerabilities/38713




© 1998-2025 E-Soft Inc. All rights reserved.