CVE-2007-6492: Input Validation
The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via an empty string in the argument to the ProcessRequestEx method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6492?
CVE-2007-6492 has been classified as a moderate severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2007-6492?
To fix CVE-2007-6492, users should update to a version of iMesh that is higher than 7.1.0.
What does CVE-2007-6492 affect?
CVE-2007-6492 affects the IMWeb.IMWebControl.1 ActiveX control in versions 7.0.0.x and 7.1.0.x and earlier of iMesh.
What is the impact of CVE-2007-6492?
The impact of CVE-2007-6492 is that it allows remote attackers to crash Internet Explorer 7 by invoking a denial of service attack.
Is CVE-2007-6492 exploited in the wild?
There have been no widely reported exploits of CVE-2007-6492 in the wild, but the vulnerability still poses a risk to affected systems.