CVE-2007-2237

5.5
MEDIUMCVSS v3.1 Base Score
15.42%
LOW RiskEPSS (97th percentile)

Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.

Published: 6/6/2007
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVSS v2 Score

7.1

AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS Score (Exploitation Probability)

15.42%LOW Exploitation Risk
97th percentile

This vulnerability has a 15.42% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.

CWE Classification

Advertisement