The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.
References
Configurations
History
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://moaxb.blogspot.com/2007/05/moaxb-03-wordviewerocx-32-multiple_03.html - | |
References | () http://osvdb.org/34334 - | |
References | () http://secunia.com/advisories/25100 - | |
References | () http://www.securityfocus.com/bid/23784 - | |
References | () http://www.vupen.com/english/advisories/2007/1634 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34027 - |
Information
Published : 2007-05-04 00:19
Updated : 2024-11-21 00:30
NVD link : CVE-2007-2496
Mitre link : CVE-2007-2496
CVE.ORG link : CVE-2007-2496
JSON object : View
Products Affected
office_ocx
- word_viewer_ocx
CWE