CVE-2007-3902

CWE-189CWE-3993 documents3 sources
Severity
9.3CRITICAL
EPSS
60.8%
top 1.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 1

Description

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDmicrosoft/internet_explorer15 versions+14
NVDmicrosoft/ie5.x, 6.0+1

🔴Vulnerability Details

2
GHSA
GHSA-27m8-q4mw-5g3g: Use-after-free vulnerability in the CRecalcProperty function in mshtml2022-05-01
CVEList
CVE-2007-3902: Use-after-free vulnerability in the CRecalcProperty function in mshtml2007-12-12
CVE-2007-3902 (CRITICAL CVSS 9.3) | Use-after-free vulnerability in the | cvebase.io