Oval Definition:oval:org.mitre.oval:def:6081
Revision Date:2014-08-18Version:44
Title:CSS Memory Corruption Vulnerability
Description:Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-0076
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Mshtml.dll/Server 2003 (32-bit)
  • Microsoft Windows XP is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR Mshtml.dll/Server 2003 (32-bit)
  • Microsoft Windows Server 2003 (32-bit) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.20996
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18203
  • OR Mshtml.dll/Vista (32-bit)
  • Microsoft Windows Vista (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22355
  • OR Mshtml.dll/Server 2008 (32-bit)
  • Microsoft Windows Server 2008 (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18203
  • OR Mshtml.dll/Server 2008 (32-bit)
  • Microsoft Windows Server 2008 (32-bit) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22355
  • OR IE7/XP x64/Server 2003 x64
  • XP x64/Server 2003 x64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR IE7/XP x64/Server 2003 x64
  • XP x64/Server 2003 x64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.20996
  • OR IE7/Vista x64
  • Microsoft Windows Vista x64 Edition is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16809
  • OR IE7/Vista x64
  • Microsoft Windows Vista x64 Edition is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.20996
  • OR IE7/Vista x64/Server 2008 x64
  • Vista x64/Server 2008 x64
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18203
  • OR IE7/Vista x64/Server 2008 x64
  • Vista x64/Server 2008 x64
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6001.22355
  • BACK