CVE-2007-4676
high · 9.3Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
9.3
CVSS
46.7%
EPSS (exploit prob.)
99th
EPSS percentile
2007-11-07
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apple | quicktime | < 7.3 |
| apple | mac_os_x | 10.3.9 |
| apple | mac_os_x | 10.4.10 |
| apple | mac_os_x | 10.5 |
| microsoft | windows_vista | all versions |
| microsoft | windows_xp | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://docs.info.apple.com/article.html?artnum=306896
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html
- http://osvdb.org/38546
- http://secunia.com/advisories/27523
- http://securityreason.com/securityalert/3351
- http://www.kb.cert.org/vuls/id/690515
- http://www.securityfocus.com/archive/1/483311/100/0/threaded
- http://www.securityfocus.com/archive/1/483313/100/0/threaded
- http://www.securityfocus.com/bid/26345
- http://www.securitytracker.com/id?1018894
- http://www.us-cert.gov/cas/techalerts/TA07-310A.html
- http://www.vupen.com/english/advisories/2007/3723
- http://www.zerodayinitiative.com/advisories/ZDI-07-066.html
- http://www.zerodayinitiative.com/advisories/ZDI-07-067.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38280
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38281
- http://docs.info.apple.com/article.html?artnum=306896
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html
- http://osvdb.org/38546
- http://secunia.com/advisories/27523
- http://securityreason.com/securityalert/3351
- http://www.kb.cert.org/vuls/id/690515
- http://www.securityfocus.com/archive/1/483311/100/0/threaded
- http://www.securityfocus.com/archive/1/483313/100/0/threaded
- http://www.securityfocus.com/bid/26345
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-4676