CVE-2007-3902

Microsoft Internet Explorer 5.01-7 - Use-After-Free via setExpression and outerHTML Manipulation

Title source: llm
STIX 2.1

Description

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26506
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1019078
Third Party Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=631
Third Party Advisory, VDB Entry vendor-advisory x_refsource_hp
http://www.securityfocus.com/archive/1/485268/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28036
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4184
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-345A.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/484887/100/0/threaded
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-073.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4582
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38713

Scores

EPSS 0.3551
EPSS Percentile 98.3%

Details

CWE
CWE-189 CWE-399
Status published
Products (17)
microsoft/ie 5.x
microsoft/ie 6.0 sp1 (2 CPE variants)
microsoft/internet_explorer 5
microsoft/internet_explorer 5.01 (5 CPE variants)
microsoft/internet_explorer 5.1
microsoft/internet_explorer 5.2.3
microsoft/internet_explorer 5.5 (4 CPE variants)
microsoft/internet_explorer 6 (2 CPE variants)
microsoft/internet_explorer 6.0
microsoft/internet_explorer 6.0.2600
... and 7 more
Published Dec 12, 2007
Tracked Since Feb 18, 2026