CVE-2007-0217
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
- Affected products
- Internet Explorer
- Microsoft Internet Explorer
- = 5.01
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 58.1% (99th percentile)
- NVD status
- Modified
- Published
- 2007-02-13
CVE-2007-0217 at NVD
1 known exploit for CVE-2007-0217
Proof-of-concept code and exploit modules indexed by Sploitus