CVE-2007-1204
Last modified
CVE-2007-1204 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.. EPSS estimates a 8.84% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows Xp | All versions | Sp2 |
References
- http://secunia.com/advisories/24822Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1323Vendor Advisory
- http://secunia.com/advisories/24822Vendor Advisory
- http://www.vupen.com/english/advisories/2007/1323Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1204?
How severe is CVE-2007-1204?
How do I fix CVE-2007-1204?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1197Multiple unspecified vulnerabilities in Epiware before 4.7.5…
- CVE-2007-1198Cross-site scripting (XSS) vulnerability in TaskFreak! befor…
- CVE-2007-1199Adobe Reader and Acrobat Trial allow remote attackers to rea…
- CVE-2007-1201Unspecified vulnerability in certain COM objects in Microsof…
- CVE-2007-1202Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, …
- CVE-2007-1203Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 …
- CVE-2007-1205Unspecified vulnerability in Microsoft Agent (msagent\agents…
- CVE-2007-1206The Virtual DOS Machine (VDM) in the Windows Kernel in Micro…
- CVE-2007-1207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-1208Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-1209Use-after-free vulnerability in the Client/Server Run-time S…
- CVE-2007-1210Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2007-1204?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
