Skip to main content

CVE-2007-0099

CVSS Score Not Available
56.54%
MEDIUM RiskEPSS (98th percentile)

Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."

Published: 1/8/2007
Modified: 4/9/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

56.54%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 56.54% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

Related Vulnerabilities