First published: Fri Jan 19 2007(Updated: )
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP_BDc.SelectedFolder property value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Common Controls Replacement Project Browsedialog Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0371 has a severity rating that indicates it can lead to a denial of service vulnerability in Internet Explorer 7.
To fix CVE-2007-0371, it is recommended to avoid using the affected ActiveX control and to update to a secure version of the software.
CVE-2007-0371 specifically affects systems using the CCRP BrowseDialog Server ActiveX control.
CVE-2007-0371 enables remote attackers to crash Internet Explorer 7 by exploiting a long input in the CCRP_BDc.SelectedFolder property.
If you encounter CVE-2007-0371, refrain from using applications that rely on the vulnerable ActiveX control and consider patching or updating potentially affected software.