Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.138
EPSS Ranking 96.1%