{"api_version":"1","generated_at":"2026-07-23T10:15:39+00:00","cve":"CVE-2007-0612","urls":{"html":"https://cve.report/CVE-2007-0612","api":"https://cve.report/api/cve/CVE-2007-0612.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0612","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0612"},"summary":{"title":"CVE-2007-0612","description":"Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-31 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://securityreason.com/securityalert/2199","name":"http://securityreason.com/securityalert/2199","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS) - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/458443/100/0/threaded","name":"http://www.securityfocus.com/archive/1/458443/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-disclosure] [SECURITY] [DSA 1254-1] New bind9 packages fix\tdenial of service","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/22288","name":"http://www.securityfocus.com/bid/22288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html","name":"http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Internet Explorer ActiveX bgColor Property Denial of Service","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://osvdb.org/32628","name":"http://osvdb.org/32628","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31867","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31867","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0612","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0612","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"5.0_ta3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"6.0","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"ie","cpe6":"7.0","cpe7":"*","cpe8":"vista","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.0.1","cpe7":"sp4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7.0","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"612","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:26:54.433Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20070128 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html"},{"name":"20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/458443/100/0/threaded"},{"name":"32628","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/32628"},{"name":"ie-activex-bgcolor-dos(31867)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31867"},{"name":"2199","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/2199"},{"name":"20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html"},{"name":"22288","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22288"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20070128 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html"},{"name":"20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/458443/100/0/threaded"},{"name":"32628","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/32628"},{"name":"ie-activex-bgcolor-dos(31867)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31867"},{"name":"2199","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/2199"},{"name":"20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html"},{"name":"22288","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22288"},{"tags":["x_refsource_MISC"],"url":"http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0612","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20070128 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0547.html"},{"name":"20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/458443/100/0/threaded"},{"name":"32628","refsource":"OSVDB","url":"http://osvdb.org/32628"},{"name":"ie-activex-bgcolor-dos(31867)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31867"},{"name":"2199","refsource":"SREASON","url":"http://securityreason.com/securityalert/2199"},{"name":"20070129 Internet Explorer 7 ActiveX bgColor property NULL pointer dereference (DoS)","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-January/052057.html"},{"name":"22288","refsource":"BID","url":"http://www.securityfocus.com/bid/22288"},{"name":"http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html","refsource":"MISC","url":"http://www.determina.com/security.research/vulnerabilities/activex-bgcolor.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0612","datePublished":"2007-01-31T11:00:00.000Z","dateReserved":"2007-01-30T00:00:00.000Z","dateUpdated":"2024-08-07T12:26:54.433Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-31 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:ie:5.0_ta3:*:*:*:*:*:*:*","matchCriteriaId":"A086C4BD-F015-45F9-AF24-763F0FDF4268"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*","matchCriteriaId":"24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:ie:7.0:*:vista:*:*:*:*:*","matchCriteriaId":"3E51CBF2-EFFD-407D-AB34-BDE69EFD60E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3A04FEA6-37B0-44B0-844F-55652ABA1F85"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp1:*:*:*:*:*:*","matchCriteriaId":"4D56FB8E-2553-47C1-82A2-9E59023780CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.0.1:sp4:*:*:*:*:*:*","matchCriteriaId":"2EB39B99-91A0-4B70-B12A-BA37F6AFBA83"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:5.5:*:*:*:*:*:*:*","matchCriteriaId":"40F8042F-C621-45AE-9F8C-70469579643A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*","matchCriteriaId":"A19F6133-25D1-44A5-B6B9-354703436783"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:*","matchCriteriaId":"ED471260-0272-431F-A91E-AC2883D92497"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7.0:beta2:*:*:*:*:*:*","matchCriteriaId":"63D18070-EC48-4904-9AE0-558F7F3B869D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"612","Ordinal":"1","Title":"CVE-2007-0612","CVE":"CVE-2007-0612","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"612","Ordinal":"1","NoteData":"Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.","Type":"Description","Title":"CVE-2007-0612"},{"CveYear":"2007","CveId":"612","Ordinal":"2","NoteData":"2007-01-31","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"612","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}