Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-0099

EPSS 56.54% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-0099

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft XML Core Services竞争条件内存破坏漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft XML Core Services(MSXML)允许使用JScript、VBScript和Visual Studio 6.0的用户开发基于XML的应用,以与其他遵循XML 1.0标准的应用程序交互操作。Microsoft XML Core Services解析XML内容的方式中存在一个竞争条件错误。如果用户浏览的网页或HTML电子邮件包含有大量嵌套标签(10到1000个),则在IFRAME中显示时JavaScript定时器会反复中断渲染进程,强制帧大约每50到100毫秒重载一次。成功利
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-0099

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-0099

Please Login to view more intelligence information

Same Patch Batch · n/a · 2007-01-08 · 21 CVEs total

CVE-2006-6901Microsoft Windows Bluetooth栈未明安全管理权限漏洞
CVE-2007-0101Spine Administrative Section 跨站请求伪造漏洞
CVE-2007-0100Perforce 任意文件重写漏洞
CVE-2006-6908Widcomm Bluetooth 蓝牙通讯缓冲区溢出漏洞
CVE-2006-6907Bluesoil Bluetooth栈未明安全漏洞
CVE-2006-6906Mac OS Bluetooth栈未明异常处理漏洞
CVE-2006-6905Widcomm Bluetooth stack 未明远程管理权限漏洞
CVE-2006-6904Broadcom Bluetooth stack 未明管理权限漏洞
CVE-2006-6903Toshiba Bluetooth stack 未明管理权限漏洞
CVE-2006-6902Microsoft Windows Mobile Pocket PC Bluetooth栈未明管理权限漏洞
CVE-2006-4097Cisco Secure Access Control Server CSRadius服务多个未明漏洞
CVE-2006-6900Apple Mac OS Bluetooth stack未明安全漏洞
CVE-2006-6899BlueZ HID不安全设备连接漏洞
CVE-2006-6898Windows Widcomm Bluetooth CarWhisperer攻击漏洞
CVE-2006-6897Windows Widcomm Bluetooth 未明目录遍历漏洞
CVE-2006-6896Plantronic Headset Bluetooth栈未授权安全漏洞
CVE-2006-6895Sony Ericsson Bluetooth栈有限可见模式未授权安全漏洞
CVE-2006-6894SPINE 多个未明安全漏洞
CVE-2006-6893Tor 高速率访问隐藏服务漏洞
CVE-2006-4098Cisco Secure Access Control Server CSRadius服务栈缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2007-0099

No comments yet


Leave a comment