CVE-2007-0947: Use After Free
Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0947?
CVE-2007-0947 has a critical severity due to its potential to allow arbitrary code execution.
How do I fix CVE-2007-0947?
To fix CVE-2007-0947, update Microsoft Internet Explorer to the latest version available for your operating system.
Which versions are affected by CVE-2007-0947?
CVE-2007-0947 affects Internet Explorer 7.0 and earlier versions, running on Windows XP SP2, Windows Vista, and Windows Server 2003 SP1 or SP2.
What type of attacks can exploit CVE-2007-0947?
CVE-2007-0947 can be exploited through remote attacks using malicious HTML objects.
Is CVE-2007-0947 a browser vulnerability?
Yes, CVE-2007-0947 is a use-after-free vulnerability specifically found in Microsoft Internet Explorer.