CVE-2007-4901
Estado: ModificadaMedia (5.8)—
The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.79%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- NVD-CWE-noinfo
Referencias
- http://aviv.raffon.net/2007/09/25/ReadyAIMFire.aspx
- http://secunia.com/advisories/26786
- http://securityreason.com/securityalert/3136
- http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1924
- http://www.securityfocus.com/archive/1/479199/100/0/threaded
- http://www.securityfocus.com/archive/1/479435/100/0/threaded
- http://www.securityfocus.com/archive/1/480587/100/0/threaded
- http://www.securityfocus.com/archive/1/480647/100/0/threaded
- http://www.securityfocus.com/bid/25659
- http://aviv.raffon.net/2007/09/25/ReadyAIMFire.aspx
- http://secunia.com/advisories/26786
- http://securityreason.com/securityalert/3136
- http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1924
- http://www.securityfocus.com/archive/1/479199/100/0/threaded
- http://www.securityfocus.com/archive/1/479435/100/0/threaded
- http://www.securityfocus.com/archive/1/480587/100/0/threaded
- http://www.securityfocus.com/archive/1/480647/100/0/threaded
- http://www.securityfocus.com/bid/25659
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4901",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-09-14T18:17:00.000",
"references": [
{
"url": "http://aviv.raffon.net/2007/09/25/ReadyAIMFire.aspx",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26786",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3136",
"source": "cve@mitre.org"
},
{
"url": "http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1924",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/479199/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/479435/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/480587/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/480647/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25659",
"source": "cve@mitre.org"
},
{
"url": "http://aviv.raffon.net/2007/09/25/ReadyAIMFire.aspx",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26786",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3136",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.coresecurity.com/index.php5?module=ContentMod&action=item&id=1924",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/479199/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/479435/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/480587/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/480647/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25659",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute arbitrary code, as demonstrated by writing arbitrary HTML to a notification window, and writing contents of arbitrary local image files to this window via IMG SRC."
},
{
"lang": "es",
"value": "El control de servidor de Internet Explorer integrado en AOL Instant Messenger (AIM) versiones 6.1.41.2 y 6.2.32.1, AIM Pro y AIM Lite, no restringe apropiadamente el uso del script web y la funcionalidad HTML de la biblioteca mshtml.dll para mensajes instantáneos entrantes, que permite a atacantes remotos colocar HTML en contextos inesperados o ejecutar código arbitrario, como es demostrado al escribir HTML arbitrario en una ventana de notificación, y al escribir contenido de archivos de imagen local arbitrarios en esta ventana por medio de IMG SRC."
}
],
"lastModified": "2026-06-16T22:44:58.483",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:aol:aim_lite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8C40F1A2-FD34-4ACD-88A4-F64E9BD7F26C"
},
{
"criteria": "cpe:2.3:a:aol:aim_pro:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAE2B57E-171E-412B-9A82-276B4FD5432C"
},
{
"criteria": "cpe:2.3:a:aol:instant_messenger:6.2.32.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6078A6ED-B8F6-476A-AAC5-CA1F42AAC1F6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}