CVE-2007-3033

Microsoft Windows Vista - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly removed and are rendered in the local zone.

Scores

EPSS 0.5815
EPSS Percentile 98.2%

Classification

CWE
CWE-79
Status draft

Affected Products (2)

microsoft/windows_vista
microsoft/windows_vista

Timeline

Published Aug 14, 2007
Tracked Since Feb 18, 2026