First published: Fri Jan 04 2008(Updated: )
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long argument to the SetPassword method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DivX | =6.6.0 | |
Internet Explorer | =7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0090 has a severity rating that indicates it can allow remote attackers to crash Internet Explorer 7.
To mitigate CVE-2008-0090, it is recommended to update DivX Player to a newer version that addresses this vulnerability.
CVE-2008-0090 affects DivX Player version 6.6.0 and Internet Explorer 7.
CVE-2008-0090 can be exploited to cause a denial of service by crashing Internet Explorer 7.
While CVE-2008-0090 pertains to older software, it may still pose a risk on systems that have not been updated.