Vulnerability Name: | CVE-2007-2393 (CCN-35359) | ||||||||
Assigned: | 2007-07-11 | ||||||||
Published: | 2007-07-11 | ||||||||
Updated: | 2018-10-30 | ||||||||
Summary: | The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-2393 Source: CCN Type: Apple Web site About the security content of QuickTime 7.2 Source: CONFIRM Type: Patch http://docs.info.apple.com/article.html?artnum=305947 Source: APPLE Type: Patch APPLE-SA-2007-07-11 Source: OSVDB Type: UNKNOWN 36135 Source: CCN Type: SA26034 Apple QuickTime Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 26034 Source: CCN Type: SECTRACK ID: 1018373 QuickTime Memory Corruption Bugs Let Remote Users Execute Arbitrary Code Source: CCN Type: Apple QuickTime Web site Apple - QuickTime Source: CCN Type: OSVDB ID: 36135 Apple QuickTime for Java Process Memory Manipulation Arbitrary Code Execution Source: BID Type: UNKNOWN 24873 Source: CCN Type: BID-24873 Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities Source: SECTRACK Type: UNKNOWN 1018373 Source: CERT Type: US Government Resource TA07-193A Source: VUPEN Type: UNKNOWN ADV-2007-2510 Source: XF Type: UNKNOWN quicktime-java-applet-code-execution(35359) Source: XF Type: UNKNOWN quicktime-java-applet-code-execution(35359) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |