CVE
- Id
- 27259
- CVE No.
- CVE-2007-3902
- Status
- Candidate
- Description
- Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."
- Phase
- Assigned (20070719)
- Votes
- None (candidate not yet proposed)
- Comments