Security Advisory

CVE-2007-2222

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2007-06-12 19:00:00
Last updated 2024-08-07 13:23:51
Assigner microsoft
CVSS score not scored
State PUBLISHED

Description

Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.