Key Information from the Vulnerability Advisory Date: August 14th, 2007 Title: Microsoft Internet Explorer substringData Heap Overflow Vulnerability ID: - ZDI-07-048 - ZDI-CAN-096 CVE ID: CVE-2007-2223 CVSS Score: Not provided Affected Vendor: Microsoft Affected Product: Internet Explorer Protection: Trend Micro TippingPoint IPS customers are protected by Digital Vaccine protection filter ID ['5098'] Vulnerability Details: Allows remote attackers to execute arbitrary code due to an integer overflow in the method of the TextNode JavaScript object under specific conditions leading to incorrect memory allocation. Additional Details: Microsoft issued an update. More details: http://www.microsoft.com/technet/security/bulletin/MS07-042.mspx Disclosure Timeline: - 2006-10-03: Vulnerability reported to vendor - 2007-08-14: Coordinated public release of advisory Credit: Anonymous