CVE-2007-1749
Microsoft Internet Explorer - Buffer Overflow
Title source: ruleDescription
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Ben Nagy & Derek Soeder · htmldoswindows
https://www.exploit-db.com/exploits/30494
References (11)
Scores
EPSS
0.7847
EPSS Percentile
99.0%
Details
Status
published
Products (3)
microsoft/internet_explorer
5.01
microsoft/internet_explorer
6
microsoft/internet_explorer
7
Published
Aug 14, 2007
Tracked Since
Feb 18, 2026