← Back

CVE-2007-2388

nvd nist
Published: May 29, 2007Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.

Affected (1)

Products: Apple: Quicktime
1 product
Quicktime
Configuration A
1 vulnerable · 42 platform
Vulnerable SoftwareAffected Versions
Version 7.1.6
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Apple
Mac Os X
Version 10.0.1
Apple
Mac Os X
Version 10.0.2
Apple
Mac Os X
Version 10.0.3
Apple
Mac Os X
Version 10.0.4
Apple
Mac Os X
Version 10.0
Apple
Mac Os X
Version 10.1.1
Apple
Mac Os X
Version 10.1.2
Apple
Mac Os X
Version 10.1.3
Apple
Mac Os X
Version 10.1.4
Apple
Mac Os X
Version 10.1.5
Apple
Mac Os X
Version 10.1
Apple
Mac Os X
Version 10.2.1
Apple
Mac Os X
Version 10.2.2
Apple
Mac Os X
Version 10.2.3
Apple
Mac Os X
Version 10.2.4
Apple
Mac Os X
Version 10.2.5
Apple
Mac Os X
Version 10.2.6
Apple
Mac Os X
Version 10.2.7
Apple
Mac Os X
Version 10.2.8
Apple
Mac Os X
Version 10.2
Apple
Mac Os X
Version 10.3.1
Apple
Mac Os X
Version 10.3.2
Apple
Mac Os X
Version 10.3.3
Apple
Mac Os X
Version 10.3.4
Apple
Mac Os X
Version 10.3.5
Apple
Mac Os X
Version 10.3.6
Apple
Mac Os X
Version 10.3.7
Apple
Mac Os X
Version 10.3.8
Apple
Mac Os X
Version 10.3.9
Apple
Mac Os X
Version 10.3
Apple
Mac Os X
Version 10.4.1
Apple
Mac Os X
Version 10.4.2
Apple
Mac Os X
Version 10.4.3
Apple
Mac Os X
Version 10.4.4
Apple
Mac Os X
Version 10.4.5
Apple
Mac Os X
Version 10.4.6
Apple
Mac Os X
Version 10.4.7
Apple
Mac Os X
Version 10.4.8
Apple
Mac Os X
Version 10.4.9
Apple
Mac Os X
Version 10.4
Microsoft
All Windows
All versions

Related CWEs

References (16)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.