Lucene search

K
nvd[email protected]NVD:CVE-2007-4674
HistoryNov 27, 2007 - 8:46 p.m.

CVE-2007-4674

2007-11-2720:46:00
CWE-189
web.nvd.nist.gov
8

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.05

Percentile

93.0%

An “integer arithmetic” error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow.

Affected configurations

Nvd
Node
applequicktimeMatch7.2_mac_os_x_v10.3.9
OR
applequicktimeMatch7.2_mac_os_x_v10.4.9
OR
applequicktimeMatch7.2_mac_os_x_v10.5
OR
applequicktimeMatch7.2windows_vista
OR
applequicktimeMatch7.2windows_xp_sp2
VendorProductVersionCPE
applequicktime7.2cpe:2.3:a:apple:quicktime:7.2:*:_mac_os_x_v10.3.9:*:*:*:*:*
applequicktime7.2cpe:2.3:a:apple:quicktime:7.2:*:_mac_os_x_v10.4.9:*:*:*:*:*
applequicktime7.2cpe:2.3:a:apple:quicktime:7.2:*:_mac_os_x_v10.5:*:*:*:*:*
applequicktime7.2cpe:2.3:a:apple:quicktime:7.2:*:windows_vista:*:*:*:*:*
applequicktime7.2cpe:2.3:a:apple:quicktime:7.2:*:windows_xp_sp2:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.05

Percentile

93.0%