Apple Security Advisories · April 2007 — Apple Security Advisories
5 advisories 5 CVEs

Apple-vendor CVEs for 2007-04. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-2175

SafariActive exploitation (sightings)CRITICAL2007-04-24

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to...

CVEs:CVE-2007-2175

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-2295

OtherEPSS <= 49%HIGH2007-04-26

Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.

CVEs:CVE-2007-2295

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-2296

OtherEPSS <= 49%HIGH2007-04-26

Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.

CVEs:CVE-2007-2296

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-2163

SafariEPSS <= 49%HIGH2007-04-22

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

CVEs:CVE-2007-2163

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-0745

macOSEPSS <= 49%HIGH2007-04-20

The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.

CVEs:CVE-2007-0745

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.