CVE-2007-0015
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
CVEs:CVE-2007-0015
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| quicktime | affected | apple | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
CVEs:CVE-2007-0015
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| quicktime | affected | apple | — | — |
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
CVEs:CVE-2007-0465
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| installer | affected | apple | — | — |
| mac_os_x | affected | apple | — | — |
Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".
CVEs:CVE-2007-0746
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a craf...
CVEs:CVE-2007-0462
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| quicktime | affected | apple | — | — |
Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.
CVEs:CVE-2007-0741
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap.
CVEs:CVE-2007-0736
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger...
CVEs:CVE-2007-0735
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.
CVEs:CVE-2007-0742
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
CVEs:CVE-2007-0729
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_preview.app | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
CVEs:CVE-2007-0747
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-...
CVEs:CVE-2007-0734
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."
CVEs:CVE-2007-0725
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
The Login Window in Apple Mac OS X 10.4 through 10.4.9 displays the software update window beneath the loginwindow authentication dialog in certain circumstances related to running scheduled tasks, which allows local users to bypass authentication cont...
CVEs:CVE-2007-0739
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.
CVEs:CVE-2007-0744
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by lis...
CVEs:CVE-2007-0743
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
The Login Window in Apple Mac OS X 10.4 through 10.4.9 does not display the screen saver authentication dialog in certain circumstances when waking from sleep, even though the "require a password to wake the computer from sleep" option is enabled, whic...
CVEs:CVE-2007-0738
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."
CVEs:CVE-2007-0732
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
The Login Window in Apple Mac OS X 10.3.9 through 10.4.9 does not properly check certain environment variables, which allows local users to gain privileges via unspecified vectors.
CVEs:CVE-2007-0737
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when...
CVEs:CVE-2007-0646
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| imovie | affected | apple | — | — |
| mac_os_x | affected | apple | — | — |
| safari | affected | apple | — | — |
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
CVEs:CVE-2007-0051
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| iphoto | affected | apple | — | — |
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request wit...
CVEs:CVE-2007-0355
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| minimal_slp_service_agent | affected | apple | — | — |
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action ...
CVEs:CVE-2007-0059
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| quicktime | affected | apple | — | — |
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permi...
CVEs:CVE-2007-0117
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10....
CVEs:CVE-2007-0342
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| safari | affected | apple | — | — |
| webkit | affected | apple | — | — |
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding ce...
CVEs:CVE-2007-0478
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| safari | affected | apple | — | — |
| webcore | affected | apple | — | — |
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a...
CVEs:CVE-2007-0229
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
| mac_os_x_server | affected | apple | — | — |
The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.
CVEs:CVE-2007-0430
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.
CVEs:CVE-2007-0022
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (...
CVEs:CVE-2007-0345
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mac_os_x | affected | apple | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.