Oval Definition:oval:org.mitre.oval:def:6294
Revision Date:2014-08-18Version:48
Title:HTML Objects Memory Corruption Vulnerability
Description:Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Objects Memory Corruption Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-1530
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • Internet Explorer 7 on all Windows XP x86, x64
  • XP x86/x64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or QFE Service branch
  • Mshtml.dll version is less than 7.0.6000.16850
  • OR QFE
  • Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21045
  • OR Internet Explorer 7 on all Windows Server 2003 x86/x64/ia64
  • Server 2003 x86/x64/ia64
  • Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or QFE Service branch
  • Mshtml.dll version is less than 7.0.6000.16850
  • OR QFE
  • Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21045
  • OR Internet Explorer 7 on all Windows Vista x86/x64
  • Vista x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 7.0.6000.16851
  • OR LDR
  • Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21046
  • OR Internet Explorer 7 on all Windows Vista x86/x64, all Server 2008 x86/x64/ia64
  • Vista x86/x64, Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 7.0.6001.18248
  • OR LDR
  • Mshtml.dll version is greater than 7.0.6001.20000
  • AND Mshtml.dll version is less than 7.0.6001.22418
  • OR Internet Explorer 7 on all Windows Vista x86/x64, Server 2008 x86/64/ia64
  • Vista x86/x64, Server 2008 x86/64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND GDR or LDR Service branch
  • Mshtml.dll version is less than 7.0.6002.18024
  • OR LDR
  • Mshtml.dll version is greater than 7.0.6002.22000
  • AND Mshtml.dll version is less than 7.0.6002.22121
  • BACK