PT-2007-4808 · Microsoft · Internet Explorer

CVE-2007-3550

·

Publicado

2007-07-03

·

Atualizado

2024-08-07

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6.0 through 7.0
Description The issue allows remote attackers to fill Zones with arbitrary domains using certain metacharacters, such as wildcards, via JavaScript. This results in a denial of service, including website suppression and resource consumption. However, it is noted that a third party has disputed this issue, stating that the zone settings cannot be manipulated.
Recommendations For Microsoft Internet Explorer versions 6.0 through 7.0, consider restricting the use of JavaScript to minimize the risk of exploitation, as a temporary workaround, until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-3550

Produtos afetados

Internet Explorer