7.2

CVE-2007-0753

Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApplemacOS X Version10.3
ApplemacOS X Version10.3.1
ApplemacOS X Version10.3.2
ApplemacOS X Version10.3.3
ApplemacOS X Version10.3.4
ApplemacOS X Version10.3.5
ApplemacOS X Version10.3.6
ApplemacOS X Version10.3.7
ApplemacOS X Version10.3.8
ApplemacOS X Version10.3.9
ApplemacOS X Version10.4
ApplemacOS X Version10.4.1
ApplemacOS X Version10.4.2
ApplemacOS X Version10.4.3
ApplemacOS X Version10.4.4
ApplemacOS X Version10.4.5
ApplemacOS X Version10.4.6
ApplemacOS X Version10.4.7
ApplemacOS X Version10.4.8
ApplemacOS X Version10.4.9
ApplemacOS X Server Version10.3
ApplemacOS X Server Version10.3.1
ApplemacOS X Server Version10.3.2
ApplemacOS X Server Version10.3.3
ApplemacOS X Server Version10.3.4
ApplemacOS X Server Version10.3.5
ApplemacOS X Server Version10.3.6
ApplemacOS X Server Version10.3.7
ApplemacOS X Server Version10.3.8
ApplemacOS X Server Version10.3.9
ApplemacOS X Server Version10.4
ApplemacOS X Server Version10.4.1
ApplemacOS X Server Version10.4.2
ApplemacOS X Server Version10.4.3
ApplemacOS X Server Version10.4.4
ApplemacOS X Server Version10.4.5
ApplemacOS X Server Version10.4.6
ApplemacOS X Server Version10.4.7
ApplemacOS X Server Version10.4.8
ApplemacOS X Server Version10.4.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.585
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.