Lucene search

K
cve[email protected]CVE-2007-5045
HistorySep 24, 2007 - 12:17 a.m.

CVE-2007-5045

2007-09-2400:17:00
CWE-94
web.nvd.nist.gov
30
cve-2007-5045
vulnerability
quicktime
apple
remote execution
command injection
security issue
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.512 Medium

EPSS

Percentile

97.6%

Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox “-chrome” argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.

Affected configurations

NVD
Node
applequicktimeRange7.1.5
OR
mozillafirefoxRange2.0.0.6

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.512 Medium

EPSS

Percentile

97.6%