First published: Wed Feb 28 2007(Updated: )
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) IsFolderAvailable or (2) RootFolder property value, different vectors than CVE-2007-0371.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Common Controls Replacement Project Browsedialog Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1162 is classified as a vulnerability that can lead to a denial of service, resulting in an Internet Explorer 7 crash.
Fixing CVE-2007-1162 involves updating the affected ActiveX control from the Common Controls Replacement Project to a patched version.
CVE-2007-1162 affects the Common Controls Replacement Project BrowseDialog Server.
CVE-2007-1162 can be exploited through remote attacks using long property values for IsFolderAvailable or RootFolder.
CVE-2007-1162 was publicly disclosed in 2007.