CVE-2007-3902: Use After Free
Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3902?
CVE-2007-3902 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2007-3902?
To mitigate CVE-2007-3902, users should upgrade to a supported version of Internet Explorer that is free from this vulnerability.
Which versions of Internet Explorer are affected by CVE-2007-3902?
CVE-2007-3902 affects Internet Explorer versions 5.01 through 7, including various service packs.
What type of attack does CVE-2007-3902 facilitate?
CVE-2007-3902 can be exploited by attackers to execute arbitrary code on the victim's machine.
Is CVE-2007-3902 still a concern for modern systems?
CVE-2007-3902 is less of a concern for modern systems as it impacts older versions of Internet Explorer that are no longer widely in use.