CVE-2007-2223
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
- Microsoft Xml Core Services
- = 3.0, 4.0, 6.0
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 48.7% (99th percentile)
- Weakness
- CWE-190, CWE-119
- NVD status
- Modified
- Published
- 2007-08-14
CVE-2007-2223 at NVD
2 known exploits for CVE-2007-2223
Proof-of-concept code and exploit modules indexed by Sploitus