The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
| Software | From | Fixed in |
|---|---|---|
| microsoft / internet_explorer | 5.01-sp4 | 5.01-sp4.x |
| microsoft / internet_explorer | 6-sp1 | 6-sp1.x |
| microsoft / windows_xp | - | - |
| microsoft / windows_2003_server | - | - |
| microsoft / windows-nt | 2008 | 2008.x |
| microsoft / windows_vista | - | - |