4.3
CVSSv2

CVE-2007-0371

Published: 19/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote malicious users to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.

Vulnerable Product Search on Vulmon Subscribe to Product

common controls replacement project browsedialog server

Exploits

<!-- ----------------------------------------------------------------------------------------------------------- BrowseDialog Class (ccrpbds6dll) Internet Explorer Denial of Service author: shinnai mail: shinnai[at]autistici[dot]org site: shinnaialtervistaorg Tested on Windows XP Professional SP2 all patched, with Internet Explorer 7 - ...