PT-2007-4808 · Microsoft · Internet Explorer

Published

2007-07-03

·

Updated

2024-08-07

·

CVE-2007-3550

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 6.0 through 7.0
Description The issue allows remote attackers to fill Zones with arbitrary domains using certain metacharacters, such as wildcards, via JavaScript. This results in a denial of service, including website suppression and resource consumption. However, it is noted that a third party has disputed this issue, stating that the zone settings cannot be manipulated.
Recommendations For Microsoft Internet Explorer versions 6.0 through 7.0, consider restricting the use of JavaScript to minimize the risk of exploitation, as a temporary workaround, until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2007-3550

Affected Products

Internet Explorer