VDB

CVE-2007-0059

CVE-2007-0059 PUBLISHED CVSS 6.800000190734863 MEDIUM

Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.

EPSS 5.68% · 92.7th percentile

Risk Scores

CVSS 2.0
6.800000190734863
EPSS Score
5.68%
92.7th percentile

Affected Products

VendorProductVersions
n/an/an/a
applequicktime3.0, 0

Timeline

  • Jan 5, 2007 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 13, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Feb 10, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 27, 2023 EPSS Score
  • Jul 19, 2023 EPSS Score
  • Sep 9, 2023 EPSS Score
  • Nov 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›