Apple Security Advisories · August 2007 — Apple Security Advisories
16 advisories 16 CVEs

Apple-vendor CVEs for 2007-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-3744

macOSEPSS <= 49%HIGH2007-08-01

Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a...

CVEs:CVE-2007-3744

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-3745

macOSEPSS <= 49%CRITICAL2007-08-01

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 contains an unsafe interface that is exposed by JDirect, which allows remote attackers to free arbitrary memory and thereby execute arbitrary code.

CVEs:CVE-2007-3745

Affected products

ProductStatusVendorPackageEcosystem
core_audio_technologies affected apple
Upstream advisory

CVE-2007-3746

macOSEPSS <= 49%CRITICAL2007-08-01

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.

CVEs:CVE-2007-3746

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
Upstream advisory

CVE-2007-3747

macOSEPSS <= 49%CRITICAL2007-08-01

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.

CVEs:CVE-2007-3747

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
Upstream advisory

CVE-2007-2406

macOSEPSS <= 49%CRITICAL2007-08-01

Quartz Composer on Apple Mac OS X 10.4.10 does not initialize a certain object pointer, which might allow user-assisted remote attackers to execute arbitrary code via a crafted Quartz Composer file.

CVEs:CVE-2007-2406

Affected products

ProductStatusVendorPackageEcosystem
quartz_composer affected apple
Upstream advisory

CVE-2007-2405

macOSEPSS <= 49%CRITICAL2007-08-01

Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file.

CVEs:CVE-2007-2405

Affected products

ProductStatusVendorPackageEcosystem
pdfkit affected apple
Upstream advisory

CVE-2007-3743

SafariEPSS <= 49%CRITICAL2007-08-03

Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.

CVEs:CVE-2007-3743

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3742

iOSEPSS <= 49%MEDIUM2007-08-01

WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike...

CVEs:CVE-2007-3742

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3748

macOSEPSS <= 49%HIGH2007-08-01

Buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in iChat on Apple Mac OS X 10.3.9 and 10.4.10 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.

CVEs:CVE-2007-3748

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
Upstream advisory

CVE-2007-2408

SafariEPSS <= 49%MEDIUM2007-08-01

WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.

CVEs:CVE-2007-2408

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-2403

macOSEPSS <= 49%MEDIUM2007-08-01

CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arbitrary FTP commands to arbitrary FTP servers.

CVEs:CVE-2007-2403

Affected products

ProductStatusVendorPackageEcosystem
cfnetwork affected apple
Upstream advisory

CVE-2007-2404

macOSEPSS <= 49%CRITICAL2007-08-01

CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: thi...

CVEs:CVE-2007-2404

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-4431

SafariEPSS <= 49%MEDIUM2007-08-20

Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript fr...

CVEs:CVE-2007-4431

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-2409

macOSEPSS <= 49%HIGH2007-08-01

Cross-domain vulnerability in WebCore on Apple Mac OS X 10.3.9 and 10.4.10 allows remote attackers to obtain sensitive information via a popup window, which is able to read the current URL of the parent window.

CVEs:CVE-2007-2409

Affected products

ProductStatusVendorPackageEcosystem
webcore affected apple
Upstream advisory

CVE-2007-2410

macOSEPSS <= 49%CRITICAL2007-08-01

WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of certain global objects when a new URL is visited in the same window, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

CVEs:CVE-2007-2410

Affected products

ProductStatusVendorPackageEcosystem
webcore affected apple
Upstream advisory

CVE-2007-4424

SafariEPSS <= 49%MEDIUM2007-08-18

Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attri...

CVEs:CVE-2007-4424

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.