← Back

CVE-2007-3902

nvd nist
Published: Dec 12, 2007Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

Affected (30)

2 products
Ie
Internet Explorer
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 5.x
Version 6.0 sp1
Version 6.0 sp2
Microsoft
Version 5.01
Version 5.01 sp1
Version 5.01 sp2
Version 5.01 sp3
Version 5.01 sp4
Version 5.1
Version 5.2.3
Version 5.5
Version 5.5 preview
Version 5.5 sp1
Version 5.5 sp2
Version 5
Version 6.0.2600
Version 6.0.2800.1106
Version 6.0.2800
Version 6.0.2900.2180
Version 6.0.2900
Version 6.0
Version 6
Version 6 sp1
Version 7.0.5730.11
Version 7.0
Version 7.0 beta1
Version 7.0 beta2
Version 7.0 beta3
Version 7.0 beta
Version 7

References (24)

Source: secure@microsoft.com
Vendor Advisory
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.