Apple Security Advisories · September 2007 — Apple Security Advisories
14 advisories 14 CVEs

Apple-vendor CVEs for 2007-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-3752

OtherEPSS <= 49%HIGH2007-09-06

Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted album cover art in the covr atom of an MP4/AAC file.

CVEs:CVE-2007-3752

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2007-5045

OtherEPSS <= 49%HIGH2007-09-24

Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML ...

CVEs:CVE-2007-5045

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-3758

macOSEPSS <= 49%CRITICAL2007-09-27

Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to con...

CVEs:CVE-2007-3758

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3760

macOSEPSS <= 49%CRITICAL2007-09-27

Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.

CVEs:CVE-2007-3760

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-4812

SafariEPSS <= 49%CRITICAL2007-09-11

Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. NO...

CVEs:CVE-2007-4812

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3753

iOSEPSS <= 49%CRITICAL2007-09-27

Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Service Discovery Protocol (SDP) packets, related to insufficient input vali...

CVEs:CVE-2007-3753

Affected products

ProductStatusVendorPackageEcosystem
iphone affected apple
iphone_os affected apple
Upstream advisory

CVE-2007-4671

macOSEPSS <= 49%MEDIUM2007-09-27

Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that c...

CVEs:CVE-2007-4671

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3756

macOSEPSS <= 49%HIGH2007-09-27

Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the...

CVEs:CVE-2007-3756

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-4673

OtherEPSS <= 49%HIGH2007-09-13

Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-200...

CVEs:CVE-2007-4673

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2007-3755

iOSEPSS <= 49%CRITICAL2007-09-27

Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.

CVEs:CVE-2007-3755

Affected products

ProductStatusVendorPackageEcosystem
iphone affected apple
iphone_os affected apple
Upstream advisory

CVE-2007-3757

iOSEPSS <= 49%MEDIUM2007-09-27

Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted "tel:" link that causes iPhone to display a different number than the number that will be dialed.

CVEs:CVE-2007-3757

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3761

iOSEPSS <= 49%CRITICAL2007-09-27

Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1 allows remote attackers to inject arbitrary web script or HTML by causing Javascript events to be applied to a frame in another domain.

CVEs:CVE-2007-3761

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2007-3754

iOSEPSS <= 49%HIGH2007-09-27

Mail in Apple iPhone 1.1.1, when using SSL, does not warn the user when the mail server changes or is not trusted, which might allow remote attackers to steal credentials and read email via a man-in-the-middle (MITM) attack.

CVEs:CVE-2007-3754

Affected products

ProductStatusVendorPackageEcosystem
iphone affected apple
iphone_os affected apple
Upstream advisory

CVE-2007-3759

iOSEPSS <= 49%MEDIUM2007-09-27

Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to attacks that the user does not expect.

CVEs:CVE-2007-3759

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.