{"api_version":"1","generated_at":"2026-04-23T15:09:03+00:00","cve":"CVE-2007-2225","urls":{"html":"https://cve.report/CVE-2007-2225","api":"https://cve.report/api/cve/CVE-2007-2225.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2225","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2225"},"summary":{"title":"CVE-2007-2225","description":"A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka \"URL Parsing Cross Domain Information Disclosure Vulnerability.\"","state":"PUBLISHED","assigner":"microsoft","published_at":"2007-06-12 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1018232","name":"http://www.securitytracker.com/id?1018232","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Windows Mail MHTML Protocol Handler Redirect Bug Lets Remote Users Obtain Information - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://archive.openmya.devnull.jp/2007.06/msg00060.html","name":"http://archive.openmya.devnull.jp/2007.06/msg00060.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"401 Authorization Required","mime":"text/html","httpstatus":"401","archivestatus":"401"},{"url":"http://www.kb.cert.org/vuls/id/682825","name":"http://www.kb.cert.org/vuls/id/682825","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#682825","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/472002/100/0/threaded","name":"http://www.securityfocus.com/archive/1/472002/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded","name":"http://www.securityfocus.com/archive/1/471947/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018231","name":"http://www.securitytracker.com/id?1018231","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Outlook Express MHTML Protocol Handler Redirect Bug Lets Remote Users Obtain Information","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-034 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://openmya.hacker.jp/hasegawa/security/ms07-034.txt","name":"http://openmya.hacker.jp/hasegawa/security/ms07-034.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24392","name":"http://www.securityfocus.com/bid/24392","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Outlook Express MHTML URL Parsing Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/35345","name":"http://osvdb.org/35345","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-163A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/25639","name":"http://secunia.com/advisories/25639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Outlook Express and Windows Mail Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2154","name":"http://www.vupen.com/english/advisories/2007/2154","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2225","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2225","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2225","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"outlook_express","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"*","cpe7":"*","cpe8":"x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"*","cpe7":"sp2","cpe8":"x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"sp1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"sp1","cpe7":"*","cpe8":"itanium","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"sp2","cpe7":"*","cpe8":"itanium","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"windows_mail","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"gold","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"gold","cpe8":"x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"*","cpe8":"professional_x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2225","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"*","cpe7":"sp2","cpe8":"professional_x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:23:51.107Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"MS07-034","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034"},{"name":"1018232","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018232"},{"name":"VU#682825","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/682825"},{"name":"SSRT071438","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"},{"name":"24392","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24392"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://openmya.hacker.jp/hasegawa/security/ms07-034.txt"},{"name":"20070622 MS07-034: Executing arbitrary script with mhtml: protocol handler","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/472002/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://archive.openmya.devnull.jp/2007.06/msg00060.html"},{"name":"35345","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35345"},{"name":"1018231","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018231"},{"name":"TA07-163A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html"},{"name":"oval:org.mitre.oval:def:2045","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045"},{"name":"25639","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25639"},{"name":"ADV-2007-2154","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2154"},{"name":"HPSBST02231","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka \"URL Parsing Cross Domain Information Disclosure Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"MS07-034","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034"},{"name":"1018232","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018232"},{"name":"VU#682825","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/682825"},{"name":"SSRT071438","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"},{"name":"24392","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24392"},{"tags":["x_refsource_MISC"],"url":"http://openmya.hacker.jp/hasegawa/security/ms07-034.txt"},{"name":"20070622 MS07-034: Executing arbitrary script with mhtml: protocol handler","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/472002/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://archive.openmya.devnull.jp/2007.06/msg00060.html"},{"name":"35345","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35345"},{"name":"1018231","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018231"},{"name":"TA07-163A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html"},{"name":"oval:org.mitre.oval:def:2045","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045"},{"name":"25639","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25639"},{"name":"ADV-2007-2154","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2154"},{"name":"HPSBST02231","tags":["vendor-advisory","x_refsource_HP"],"url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2007-2225","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka \"URL Parsing Cross Domain Information Disclosure Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"MS07-034","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-034"},{"name":"1018232","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018232"},{"name":"VU#682825","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/682825"},{"name":"SSRT071438","refsource":"HP","url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"},{"name":"24392","refsource":"BID","url":"http://www.securityfocus.com/bid/24392"},{"name":"http://openmya.hacker.jp/hasegawa/security/ms07-034.txt","refsource":"MISC","url":"http://openmya.hacker.jp/hasegawa/security/ms07-034.txt"},{"name":"20070622 MS07-034: Executing arbitrary script with mhtml: protocol handler","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/472002/100/0/threaded"},{"name":"http://archive.openmya.devnull.jp/2007.06/msg00060.html","refsource":"MISC","url":"http://archive.openmya.devnull.jp/2007.06/msg00060.html"},{"name":"35345","refsource":"OSVDB","url":"http://osvdb.org/35345"},{"name":"1018231","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018231"},{"name":"TA07-163A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-163A.html"},{"name":"oval:org.mitre.oval:def:2045","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2045"},{"name":"25639","refsource":"SECUNIA","url":"http://secunia.com/advisories/25639"},{"name":"ADV-2007-2154","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2154"},{"name":"HPSBST02231","refsource":"HP","url":"http://www.securityfocus.com/archive/1/471947/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2007-2225","datePublished":"2007-06-12T20:00:00.000Z","dateReserved":"2007-04-24T00:00:00.000Z","dateUpdated":"2024-08-07T13:23:51.107Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-12 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:*:*:x64:*:*:*:*:*","matchCriteriaId":"CD264C73-360E-414D-BE22-192F92E5A0A3"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*","matchCriteriaId":"6881476D-81A2-4DFD-AC77-82A8D08A0568"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*","matchCriteriaId":"644E2E89-F3E3-4383-B460-424D724EE62F"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*","matchCriteriaId":"7D11FC8D-59DD-4CAC-B4D3-DABB7A9903F1"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:sp2:*:itanium:*:*:*:*:*","matchCriteriaId":"D21D1DFE-F61B-407E-A945-4F42F86947B0"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:*:professional_x64:*:*:*:*:*","matchCriteriaId":"E0BBA081-24D5-4990-882F-69CB05CC28CF"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*","matchCriteriaId":"9B339C33-8896-4896-88FF-88E74FDBC543"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*","matchCriteriaId":"1AB9988B-5A9C-4F6D-BCCC-4D03AC6E4CF9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:outlook_express:6.0:*:*:*:*:*:*:*","matchCriteriaId":"85FD3557-956D-4A96-8AA5-5FD9DB87FD11"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:gold:*:*:*:*:*:*","matchCriteriaId":"D34A558F-A656-43EB-AC52-C3710F77CDD8"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:gold:x64:*:*:*:*:*","matchCriteriaId":"F9DC56EB-EDC4-4DFE-BA9B-B17FF4A91734"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:windows_mail:*:*:*:*:*:*:*:*","matchCriteriaId":"0BDD015F-267D-4E33-885B-6A14F493CCC5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2225","Ordinal":"1","Title":"CVE-2007-2225","CVE":"CVE-2007-2225","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2225","Ordinal":"1","NoteData":"A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka \"URL Parsing Cross Domain Information Disclosure Vulnerability.\"","Type":"Description","Title":"CVE-2007-2225"},{"CveYear":"2007","CveId":"2225","Ordinal":"2","NoteData":"2007-06-12","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2225","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}