9.3
CVSSv2

CVE-2007-2223

Published: 14/08/2007 Updated: 27/02/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Microsoft XML Core Services (MSXML) 3.0 up to and including 6.0 allows remote malicious users to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft xml_core_services 3.0

microsoft xml_core_services 6.0

microsoft xml_core_services 4.0

microsoft xml_core_services 5.0

Exploits

source: wwwsecurityfocuscom/bid/25301/info Microsoft XML Core Services is prone to an integer-overflow vulnerability because the application fails to ensure that integer values are not overrun Attackers can exploit this issue by enticing unsuspecting users to view malicious web content Specially crafted scripts could issue requests to ...