CVE-2007-1204
Last modified
CVE-2007-1204 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.. EPSS estimates a 8.84% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows Xp | All versions | Sp2 |
References
- http://secunia.com/advisories/24822Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1323Vendor Advisory
- http://secunia.com/advisories/24822Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1323Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1204?
How severe is CVE-2007-1204?
How do I fix CVE-2007-1204?
Are you affected by CVE-2007-1204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
