First published: Fri Jan 19 2007(Updated: )
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Common Controls Replacement Project FolderTreeview ActiveX Control | ||
Microsoft Internet Explorer | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-0356 is considered high due to its potential to cause denial of service by crashing Internet Explorer 7.
CVE-2007-0356 impacts users by causing Internet Explorer 7 to crash when a maliciously long property value is used.
CVE-2007-0356 specifically affects Microsoft Internet Explorer version 7.0.
To mitigate the risks of CVE-2007-0356, it is recommended to avoid using the affected ActiveX control and consider disabling ActiveX altogether.
As of now, there is no specific patch released for CVE-2007-0356, but reviewing security updates from Microsoft is advisable.