CVE-2007-1749

Microsoft Internet Explorer - Buffer Overflow

Title source: rule

Description

Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ben Nagy & Derek Soeder · htmldoswindows
https://www.exploit-db.com/exploits/30494

Scores

EPSS 0.7847
EPSS Percentile 99.0%

Details

Status published
Products (3)
microsoft/internet_explorer 5.01
microsoft/internet_explorer 6
microsoft/internet_explorer 7
Published Aug 14, 2007
Tracked Since Feb 18, 2026