Record summary

CVE-2007-1749 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.

Description

Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft Internet Explorer 5.0.1 - Vector Markup Language 'VGX.dll' Remote Buffer OverflowExploitDB exploitby Ben Nagy & Derek SoederNot analyzed1 file
ExploitDB

PoC details

References

12