Oval Definition:oval:org.mitre.oval:def:6164
Revision Date:2014-08-18Version:46
Title:Page Transition Memory Corruption Vulnerability
Description:Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-0551
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • IE6/Windows 2000
  • Microsoft Windows 2000 is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.2800.1625
  • OR IE6/XP
  • Microsoft Windows XP is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.2900.3527
  • OR IE6/XP
  • Microsoft Windows XP (32-bit) is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.2900.5764
  • OR IE6/Server 2003 (32-bit)
  • Microsoft Windows Server 2003 (32-bit) is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.3304
  • OR IE6/Server 2003 (32-bit)
  • Microsoft Windows Server 2003 (32-bit) is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.4470
  • OR IE6/XP x64/Server 2003 x64
  • XP x64/Server 2003 x64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.3304
  • OR IE6/XP x64/Server 2003 x64
  • XP x64/Server 2003 x64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.4470
  • OR IE6/Server 2003 (ia64)
  • Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.3304
  • OR IE6/Server 2003 (ia64)
  • Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 6 is installed
  • AND Mshtml.dll version is less than 6.0.3790.4470
  • OR IE7/XP x86/x64
  • XP x86/x64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16825
  • OR IE7/XP x86/x64
  • XP x86/x64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21015
  • OR IE7/Server 2003 x86/x64/ia64
  • Server 2003 x86/x64/ia64
  • Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16825
  • OR IE7/Server 2003 x86/x64/ia64
  • Server 2003 x86/x64/ia64
  • Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21015
  • OR Mshtml.dll/Vista x86/x64
  • Vista x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16830
  • OR Mshtml.dll/Vista x86/x64
  • Vista x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21023
  • OR Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64
  • Vista x86/x64/Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.16000
  • AND Mshtml.dll version is less than 7.0.6001.18226
  • OR Mshtml.dll/Vista x86/x64/Server 2008 x86/x64/ia64
  • Vista x86/x64/Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22389
  • BACK