Oval Definition:oval:org.mitre.oval:def:6000
Revision Date:2014-08-18Version:44
Title:Uninitialized Memory Corruption Vulnerability
Description:Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-0075
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • IE7/XP
  • Microsoft Windows XP is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR IE7/Server 2003 (32-bit)
  • Microsoft Windows Server 2003 (32-bit) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.20996
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18203
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22355
  • OR Mshtml.dll/Server 2008 (32-bit)
  • Microsoft Windows Server 2008 (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18203
  • OR Mshtml.dll/Server 2008 (32-bit)
  • Microsoft Windows Server 2008 (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22355
  • OR IE7/XP x86/x64
  • XP x64/Server 2003 x64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR IE7/XP x64/Server 2003 x64
  • XP x64/Server 2003 x64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.20996
  • OR IE7/Vista x64
  • Microsoft Windows Vista x64 Edition is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR IE7/Vista x64
  • Microsoft Windows Vista x64 Edition is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.20996
  • OR IE7/Vista x64/Server 2008 x64
  • Vista x64/Server 2008 x64
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18203
  • OR IE7/Vista x64/Server 2008 x64
  • Vista x64/Server 2008 x64
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6001.22355
  • BACK