Apple Security Advisories · July 2007 — Apple Security Advisories
12 advisories 12 CVEs

Apple-vendor CVEs for 2007-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-2394

macOSWeaponized exploitHIGH2007-07-12

Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory alloca...

CVEs:CVE-2007-2394

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-3944

iOSPoC exploitHIGH2007-07-23

Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via ...

CVEs:CVE-2007-3944

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
webkit affected apple
Upstream advisory

CVE-2007-3798

OtherEPSS 49-79%CRITICAL2007-07-16

Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.

CVEs:CVE-2007-3798

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-2396

OtherEPSS <= 49%HIGH2007-07-12

The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets.

CVEs:CVE-2007-2396

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-2397

OtherEPSS <= 49%HIGH2007-07-12

QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.

CVEs:CVE-2007-2397

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-2393

OtherEPSS <= 49%HIGH2007-07-12

The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.

CVEs:CVE-2007-2393

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-2392

macOSEPSS <= 49%HIGH2007-07-12

Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.

CVEs:CVE-2007-2392

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-4045

OtherEPSS <= 49%HIGH2007-07-27

The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of ser...

CVEs:CVE-2007-4045

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

CVE-2007-3828

macOSEPSS <= 49%HIGH2007-07-17

Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbitrary code via unspecified vectors, a related issue to CVE-2007-2386.

CVEs:CVE-2007-3828

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-2402

OtherEPSS <= 49%HIGH2007-07-12

QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.

CVEs:CVE-2007-2402

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-3718

SafariEPSS <= 49%HIGH2007-07-12

Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.

CVEs:CVE-2007-3718

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3514

SafariEPSS <= 49%HIGH2007-07-03

Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the docu...

CVEs:CVE-2007-3514

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.