Security Advisory

CVE-2007-1749

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-08-14 22:00:00
Last updated 2024-08-07 13:06:26
Assigner microsoft
CVSS score not scored
State PUBLISHED

Description

Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.