CVE-2007-0646
Apple Mac OSX 10.4.x - iMovie HD '.imovieproj' Filename Format String
Severity Score
6.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
Una vulnerabilidad de cadena de formato en iMovie HD versión 6.0.3 y Safari en Apple Mac OS X versiones 10.4 hasta 10.4.10, permite a atacantes remotos asistidos por el usuario causar una denegación de servicio (bloqueo de aplicación) por medio de los especificadores de cadena de formato en un nombre de archivo, que no es manejado apropiadamente cuando llaman a la función NSRunCriticalAlertPanel de Apple AppKit.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-01-30 First Exploit
- 2007-01-31 CVE Reserved
- 2007-02-01 CVE Published
- 2024-08-07 CVE Updated
- 2024-12-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://docs.info.apple.com/article.html?artnum=305391 | X_refsource_confirm | |
http://docs.info.apple.com/article.html?artnum=307041 | X_refsource_confirm | |
http://www.securityfocus.com/bid/22326 | Vdb Entry | |
http://www.securityfocus.com/bid/26444 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-109A.html | Third Party Advisory | |
http://www.us-cert.gov/cas/techalerts/TA07-319A.html | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/29551 | 2007-01-30 | |
http://www.digitalmunition.com/MOAB-30-01-2007.html | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html | 2011-03-07 | |
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html | 2011-03-07 | |
http://secunia.com/advisories/24966 | 2011-03-07 | |
http://secunia.com/advisories/27643 | 2011-03-07 | |
http://www.vupen.com/english/advisories/2007/1470 | 2011-03-07 | |
http://www.vupen.com/english/advisories/2007/3868 | 2011-03-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4 Search vendor "Apple" for product "Mac Os X" and version "10.4" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.1 Search vendor "Apple" for product "Mac Os X" and version "10.4.1" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.2 Search vendor "Apple" for product "Mac Os X" and version "10.4.2" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.3 Search vendor "Apple" for product "Mac Os X" and version "10.4.3" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.4 Search vendor "Apple" for product "Mac Os X" and version "10.4.4" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.5 Search vendor "Apple" for product "Mac Os X" and version "10.4.5" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.6 Search vendor "Apple" for product "Mac Os X" and version "10.4.6" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.7 Search vendor "Apple" for product "Mac Os X" and version "10.4.7" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.8 Search vendor "Apple" for product "Mac Os X" and version "10.4.8" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.9 Search vendor "Apple" for product "Mac Os X" and version "10.4.9" | - |
Safe
|
Apple Search vendor "Apple" | Imovie Search vendor "Apple" for product "Imovie" | 6.0.3 Search vendor "Apple" for product "Imovie" and version "6.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.10 Search vendor "Apple" for product "Mac Os X" and version "10.4.10" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4 Search vendor "Apple" for product "Mac Os X" and version "10.4" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.1 Search vendor "Apple" for product "Mac Os X" and version "10.4.1" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.2 Search vendor "Apple" for product "Mac Os X" and version "10.4.2" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.3 Search vendor "Apple" for product "Mac Os X" and version "10.4.3" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.4 Search vendor "Apple" for product "Mac Os X" and version "10.4.4" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.5 Search vendor "Apple" for product "Mac Os X" and version "10.4.5" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.6 Search vendor "Apple" for product "Mac Os X" and version "10.4.6" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.7 Search vendor "Apple" for product "Mac Os X" and version "10.4.7" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.8 Search vendor "Apple" for product "Mac Os X" and version "10.4.8" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.9 Search vendor "Apple" for product "Mac Os X" and version "10.4.9" | - |
Safe
|
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | * | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.10 Search vendor "Apple" for product "Mac Os X" and version "10.4.10" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4 Search vendor "Apple" for product "Mac Os X" and version "10.4" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.1 Search vendor "Apple" for product "Mac Os X" and version "10.4.1" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.2 Search vendor "Apple" for product "Mac Os X" and version "10.4.2" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.3 Search vendor "Apple" for product "Mac Os X" and version "10.4.3" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.4 Search vendor "Apple" for product "Mac Os X" and version "10.4.4" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.5 Search vendor "Apple" for product "Mac Os X" and version "10.4.5" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.6 Search vendor "Apple" for product "Mac Os X" and version "10.4.6" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.7 Search vendor "Apple" for product "Mac Os X" and version "10.4.7" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.8 Search vendor "Apple" for product "Mac Os X" and version "10.4.8" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.9 Search vendor "Apple" for product "Mac Os X" and version "10.4.9" | - |
Safe
|
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.3.9 Search vendor "Apple" for product "Mac Os X" and version "10.3.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.10 Search vendor "Apple" for product "Mac Os X" and version "10.4.10" | - |
Safe
|