Apple Security Advisories · January 2007 — Apple Security Advisories
29 advisories 29 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2007-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-0015

OtherExploitedVulnCheck KEV listedCRITICAL2007-01-01

Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.

CVEs:CVE-2007-0015

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple — —
Upstream advisory

CVE-2007-0465

macOSPoC exploitCRITICAL2007-01-18

Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.

CVEs:CVE-2007-0465

Affected products

ProductStatusVendorPackageEcosystem
installer affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0746

macOSPoC exploitHIGH2007-01-09

Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".

CVEs:CVE-2007-0746

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0462

macOSPoC exploitHIGH2007-01-26

The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a craf...

CVEs:CVE-2007-0462

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
quicktime affected apple — —
Upstream advisory

CVE-2007-0741

macOSPoC exploitCRITICAL2007-01-09

Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.

CVEs:CVE-2007-0741

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0736

macOSPoC exploitHIGH2007-01-09

Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.

CVEs:CVE-2007-0736

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0735

macOSPoC exploitHIGH2007-01-09

Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger...

CVEs:CVE-2007-0735

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0742

macOSPoC exploitHIGH2007-01-09

The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.

CVEs:CVE-2007-0742

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0729

macOSPoC exploitHIGH2007-01-09

Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.

CVEs:CVE-2007-0729

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_preview.app affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0747

macOSPoC exploitHIGH2007-01-09

load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.

CVEs:CVE-2007-0747

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0734

macOSPoC exploitCRITICAL2007-01-09

fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-...

CVEs:CVE-2007-0734

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0725

macOSPoC exploitHIGH2007-01-09

Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."

CVEs:CVE-2007-0725

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0739

macOSPoC exploitHIGH2007-01-09

The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication cont...

CVEs:CVE-2007-0739

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0744

macOSPoC exploitHIGH2007-01-09

SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.

CVEs:CVE-2007-0744

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0743

macOSPoC exploitMEDIUM2007-01-09

URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by lis...

CVEs:CVE-2007-0743

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0738

macOSPoC exploitHIGH2007-01-09

The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the "require a password to wake the computer from sleep" option is enabled, whic...

CVEs:CVE-2007-0738

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0732

macOSPoC exploitHIGH2007-01-09

Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."

CVEs:CVE-2007-0732

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0737

macOSPoC exploitMEDIUM2007-01-09

The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors.

CVEs:CVE-2007-0737

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0646

macOSEPSS <= 49%HIGH2007-01-09

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when...

CVEs:CVE-2007-0646

Affected products

ProductStatusVendorPackageEcosystem
imovie affected apple — —
mac_os_x affected apple — —
safari affected apple — —
Upstream advisory

CVE-2007-0051

OtherEPSS <= 49%CRITICAL2007-01-04

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.

CVEs:CVE-2007-0051

Affected products

ProductStatusVendorPackageEcosystem
iphoto affected apple — —
Upstream advisory

CVE-2007-0355

macOSEPSS <= 49%HIGH2007-01-19

Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request wit...

CVEs:CVE-2007-0355

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
minimal_slp_service_agent affected apple — —
Upstream advisory

CVE-2007-0059

OtherEPSS <= 49%CRITICAL2007-01-05

Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action ...

CVEs:CVE-2007-0059

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple — —
Upstream advisory

CVE-2007-0117

macOSEPSS <= 49%HIGH2007-01-09

DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permi...

CVEs:CVE-2007-0117

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0342

macOSEPSS <= 49%HIGH2007-01-18

WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10....

CVEs:CVE-2007-0342

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
safari affected apple — —
webkit affected apple — —
Upstream advisory

CVE-2007-0478

macOSEPSS <= 49%CRITICAL2007-01-25

WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding ce...

CVEs:CVE-2007-0478

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
webcore affected apple — —
Upstream advisory

CVE-2007-0229

macOSEPSS <= 49%HIGH2007-01-10

Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a...

CVEs:CVE-2007-0229

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
mac_os_x_server affected apple — —
Upstream advisory

CVE-2007-0430

macOSEPSS <= 49%HIGH2007-01-23

The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.

CVEs:CVE-2007-0430

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0022

macOSEPSS <= 49%HIGH2007-01-09

Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.

CVEs:CVE-2007-0022

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2007-0345

macOSEPSS <= 49%HIGH2007-01-18

The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (...

CVEs:CVE-2007-0345

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.