CVE Published: 14/08/2007 |
CVE Updated: 07/08/2024 |
CVE Year: 2007 Source: microsoft |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2007-1749 Description
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.