{
    "id": "CVE-2007-2222",
    "published": "2007-06-12 19:30:00",
    "last_modified": "2026-06-16 22:39:10",
    "cvss_score": "9.3",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
    "cwe": "CWE-119",
    "description": "Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.",
    "epss_score": "0.54738",
    "epss_percentile": "0.98991",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:06",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "microsoft",
            "product": "internet_explorer"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2000"
        },
        {
            "vendor": "microsoft",
            "product": "windows_2003_server"
        },
        {
            "vendor": "microsoft",
            "product": "windows_vista"
        },
        {
            "vendor": "microsoft",
            "product": "windows_xp"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "4065",
            "title": "Microsoft Speech API ActiveX Control (Windows 2000 SP4) - Remote Buffer Overflow (MS07-033)",
            "date": "2007-06-13",
            "url": "https://www.exploit-db.com/exploits/4065"
        },
        {
            "source": "exploit-db",
            "ref_id": "4066",
            "title": "Microsoft Speech API ActiveX Control (Windows XP SP2) - Remote Buffer Overflow (MS07-033)",
            "date": "2007-06-13",
            "url": "https://www.exploit-db.com/exploits/4066"
        }
    ],
    "refs_list": [
        "http://osvdb.org/35353",
        "http://retrogod.altervista.org/win_speech_2k_sp4.html",
        "http://retrogod.altervista.org/win_speech_xp_sp2.html",
        "http://secunia.com/advisories/25627",
        "http://securitytracker.com/id?1018235",
        "http://www.exploit-db.com/exploits/4065",
        "http://www.kb.cert.org/vuls/id/507433",
        "http://www.securityfocus.com/archive/1/471947/100/0/threaded",
        "http://www.securityfocus.com/bid/24426",
        "http://www.us-cert.gov/cas/techalerts/TA07-163A.html",
        "http://www.vupen.com/english/advisories/2007/2153",
        "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/34630",
        "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2031",
        "http://osvdb.org/35353",
        "http://retrogod.altervista.org/win_speech_2k_sp4.html",
        "http://retrogod.altervista.org/win_speech_xp_sp2.html",
        "http://secunia.com/advisories/25627",
        "http://securitytracker.com/id?1018235",
        "http://www.exploit-db.com/exploits/4065",
        "http://www.kb.cert.org/vuls/id/507433",
        "http://www.securityfocus.com/archive/1/471947/100/0/threaded",
        "http://www.securityfocus.com/bid/24426",
        "http://www.us-cert.gov/cas/techalerts/TA07-163A.html",
        "http://www.vupen.com/english/advisories/2007/2153"
    ]
}