Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonstrated by setInterval functions that set location.href within a try/catch expression, aka the "bait & switch vulnerability" or "Race Condition Cross-Domain Information Disclosure Vulnerability."
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T14:05:29.414Z

Reserved: 2007-06-06T00:00:00

Link: CVE-2007-3091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-06-06T21:30:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-3091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses