{"api_version":"1","generated_at":"2026-07-24T21:51:35+00:00","cve":"CVE-2007-1204","urls":{"html":"https://cve.report/CVE-2007-1204","api":"https://cve.report/api/cve/CVE-2007-1204.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1204","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1204"},"summary":{"title":"CVE-2007-1204","description":"Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.","state":"PUBLISHED","assigner":"microsoft","published_at":"2007-04-10 21:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:A/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:A/AC:H/Au:N/C:C/I:C/A:C","baseScore":6.8,"accessVector":"ADJACENT_NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-019","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-019","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-019 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23371","name":"http://www.securityfocus.com/bid/23371","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows UPnP Remote Stack Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1323","name":"http://www.vupen.com/english/advisories/2007/1323","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2049","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2049","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24822","name":"http://secunia.com/advisories/24822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft Windows XP UPnP Memory Corruption Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded","name":"http://www.securityfocus.com/archive/1/466331/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/34010","name":"http://www.osvdb.org/34010","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1017895","name":"http://www.securitytracker.com/id?1017895","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Windows XP Universal Plug and Play Lets Remote Users on the Local Subnet Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1204","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1204","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1204","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:50:34.927Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1017895","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1017895"},{"name":"HPSBST02208","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded"},{"name":"ADV-2007-1323","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1323"},{"name":"24822","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24822"},{"name":"oval:org.mitre.oval:def:2049","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2049"},{"name":"20070410 Microsoft Windows Universal Plug and Play Memory Corruption Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509"},{"name":"34010","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/34010"},{"name":"MS07-019","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-019"},{"name":"SSRT071365","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded"},{"name":"23371","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23371"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-04-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"1017895","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1017895"},{"name":"HPSBST02208","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded"},{"name":"ADV-2007-1323","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1323"},{"name":"24822","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24822"},{"name":"oval:org.mitre.oval:def:2049","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2049"},{"name":"20070410 Microsoft Windows Universal Plug and Play Memory Corruption Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509"},{"name":"34010","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/34010"},{"name":"MS07-019","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-019"},{"name":"SSRT071365","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded"},{"name":"23371","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23371"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2007-1204","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1017895","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1017895"},{"name":"HPSBST02208","refsource":"HP","url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded"},{"name":"ADV-2007-1323","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1323"},{"name":"24822","refsource":"SECUNIA","url":"http://secunia.com/advisories/24822"},{"name":"oval:org.mitre.oval:def:2049","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2049"},{"name":"20070410 Microsoft Windows Universal Plug and Play Memory Corruption Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509"},{"name":"34010","refsource":"OSVDB","url":"http://www.osvdb.org/34010"},{"name":"MS07-019","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-019"},{"name":"SSRT071365","refsource":"HP","url":"http://www.securityfocus.com/archive/1/466331/100/200/threaded"},{"name":"23371","refsource":"BID","url":"http://www.securityfocus.com/bid/23371"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2007-1204","datePublished":"2007-04-10T21:00:00.000Z","dateReserved":"2007-03-02T00:00:00.000Z","dateUpdated":"2024-08-07T12:50:34.927Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-04-10 21:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:H/Au:N/C:C/I:C/A:C","baseScore":6.8,"accessVector":"ADJACENT_NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.2,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*","matchCriteriaId":"9B339C33-8896-4896-88FF-88E74FDBC543"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1204","Ordinal":"1","Title":"CVE-2007-1204","CVE":"CVE-2007-1204","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1204","Ordinal":"1","NoteData":"Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.","Type":"Description","Title":"CVE-2007-1204"},{"CveYear":"2007","CveId":"1204","Ordinal":"2","NoteData":"2007-04-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1204","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}