VDB
CVE-2007-0462
CVE-2007-0462
PUBLISHED
CVSS 10 CRITICAL
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
EPSS 6.65% · 93.7th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
6.65%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | mac_os_x | 10.4.8 |
| apple | quicktime | 7.1.3 |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Sep 14, 2023 EPSS Score
References
- 32696 vdb
- 22207 vdb
- 23859 third-party-advisory
- macos-argb-dos(31698) vdb
- http://projects.info-pull.com/moab/MOAB-23-01-2007.html url
- ADV-2007-0337 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-0462 advisory