CVE-2007-2175
Last modified
CVE-2007-2175 is a vulnerability of currently unknown severity. Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.. EPSS estimates a 83.80% chance of exploitation in the next 30 days.
Description
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | All versions |
References
- http://www.kb.cert.org/vuls/id/420668US Government Resource
- http://www.kb.cert.org/vuls/id/420668US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2175?
How severe is CVE-2007-2175?
How do I fix CVE-2007-2175?
Are you affected by CVE-2007-2175?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
