VDB
CVE-2007-0051
CVE-2007-0051
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary code via a crafted photocast with format string specifiers in the title of an RSS iPhoto feed.
EPSS 9.10% · 95.1th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
9.10%
95.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | iphoto | 6.0.5 |
Timeline
- Jan 4, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Oct 1, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- 20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability' mailing-list
- http://docs.info.apple.com/article.html?artnum=305215 url
- 3080 exploit
- 23615 third-party-advisory
- 21871 vdb
- http://projects.info-pull.com/moab/MOAB-04-01-2007.html url
- 31165 vdb
- 20070104 DMA[2007-0104a] - 'iLife iPhoto Photocasing Format String Vulnerability' mailing-list
- APPLE-SA-2007-03-13 vendor-advisory
- ADV-2007-0057 vdb
- http://www.digitalmunition.com/DMA%5B2007-0104a%5D.txt url
- iphoto-xmltitle-format-string(31281) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-0051 advisory
- http://www.digitalmunition.com/DMA[2007-0104a].txt url