Lucene search

K
cveMitreCVE-2007-4677
HistoryNov 07, 2007 - 11:46 p.m.

CVE-2007-4677

2007-11-0723:46:00
CWE-119
mitre
web.nvd.nist.gov
32
cve-2007-4677
apple quicktime
buffer overflow
remote code execution
color table atom
ctab
movie file
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.801

Percentile

98.4%

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsing the color table atom (CTAB) in a movie file, related to the CTAB RGB values.

Affected configurations

Nvd
Node
applequicktimeRange<7.3
AND
applemac_os_xMatch10.3.9
OR
applemac_os_xMatch10.4.10
OR
applemac_os_xMatch10.5
OR
microsoftwindows_vistaMatch-
OR
microsoftwindows_xpMatch-sp2
VendorProductVersionCPE
applequicktime*cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*
applemac_os_x10.3.9cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
applemac_os_x10.4.10cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:*
applemac_os_x10.5cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
microsoftwindows_vista-cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*
microsoftwindows_xp-cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.801

Percentile

98.4%