← All CVEs

CVE-2007-4676

high · 9.3

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.

9.3
CVSS
46.7%
EPSS (exploit prob.)
99th
EPSS percentile
2007-11-07
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
applequicktime< 7.3
applemac_os_x10.3.9
applemac_os_x10.4.10
applemac_os_x10.5
microsoftwindows_vistaall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-4676