PT-2007-2709 · Microsoft+1 · Internet Explorer+2

Shinnai

·

Published

2007-03-06

·

Updated

2017-10-11

·

CVE-2007-1294

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions DivX Player version 1.3.0
Description The issue is related to a certain ActiveX control in the DivXBrowserPlugin, which allows remote attackers to cause a denial of service, resulting in an Internet Explorer 7 crash. This occurs when large values are passed to DivxWP.Resize, related to resizing images.
Recommendations For DivX Player version 1.3.0, consider disabling the DivxWP.Resize function to prevent the denial of service issue until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1294

Affected Products

Divx Player
Divxbrowserplugin
Internet Explorer