First published: Wed Mar 07 2007(Updated: )
A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DivX Web Player | =1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1294 has a moderate severity rating due to its ability to crash Internet Explorer 7.
To fix CVE-2007-1294, users should update to a newer version of the DivX Web Player that addresses the vulnerability.
CVE-2007-1294 specifically affects the DivX Web Player version 1.3.0.
CVE-2007-1294 is exploited through the DivxWP.Resize method, which can be manipulated using maliciously crafted input.
CVE-2007-1294 is categorized as a denial of service vulnerability.