Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-0099

Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.554
EPSS Ranking 97.9%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2007-0099


Contact Us

Shodan ® - All rights reserved