← Back

CVE-2007-4848

nvd nist
Published: Sep 12, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have associated images via a res:// URI in the src property of a JavaScript Image object, as demonstrated by the URI for a bitmap image resource within a (1) .exe or (2) .dll file.

Affected (44)

2 products
Ie
Internet Explorer
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 4.x
Version 5.0 sp1
Version 5.0 sp4
Version 5.0_ta3
Version 5.x
Version 6.0 sp1
Version 6.0 sp2
Microsoft
Version 4.0.1
Version 4.0
Version 4.1
Version 4.5
Version 5.0.1
Version 5.0.1 sp1
Version 5.0.1 sp2
Version 5.0.1 sp3
Version 5.0.1 sp4
Version 5.01
Version 5.01 sp1
Version 5.01 sp2
Version 5.01 sp3
Version 5.01 sp4
Version 5.0
Version 5.1
Version 5.2.3
Version 5.5
Version 5.5 preview
Version 5.5 sp1
Version 5.5 sp2
Version 5
Version 6.0.2600
Version 6.0.2800.1106
Version 6.0.2800
Version 6.0.2900.2180
Version 6.0.2900
Version 6.0
Version 6
Version 6 sp1
Version 7.0.5730.11
Version 7.0
Version 7.0 beta1
Version 7.0 beta2
Version 7.0 beta3
Version 7.0 beta
Version 7

References (4)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

Timeline

No history available yet.