6.8

CVE-2007-3746

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.

Data is provided by the National Vulnerability Database (NVD)
AppleIchat
   ApplemacOS X Version10.3
   ApplemacOS X Version10.3.1
   ApplemacOS X Version10.3.2
   ApplemacOS X Version10.3.3
   ApplemacOS X Version10.3.4
   ApplemacOS X Version10.3.5
   ApplemacOS X Version10.3.6
   ApplemacOS X Version10.3.7
   ApplemacOS X Version10.3.8
   ApplemacOS X Version10.3.9
   ApplemacOS X Version10.4
   ApplemacOS X Version10.4.2
   ApplemacOS X Version10.4.3
   ApplemacOS X Version10.4.4
   ApplemacOS X Version10.4.5
   ApplemacOS X Version10.4.6
   ApplemacOS X Version10.4.7
   ApplemacOS X Version10.4.8
   ApplemacOS X Version10.4.9
   ApplemacOS X Version10.4.10
   ApplemacOS X Server Version10.3
   ApplemacOS X Server Version10.3.1
   ApplemacOS X Server Version10.3.2
   ApplemacOS X Server Version10.3.3
   ApplemacOS X Server Version10.3.4
   ApplemacOS X Server Version10.3.5
   ApplemacOS X Server Version10.3.6
   ApplemacOS X Server Version10.3.7
   ApplemacOS X Server Version10.3.8
   ApplemacOS X Server Version10.3.9
   ApplemacOS X Server Version10.4
   ApplemacOS X Server Version10.4.1
   ApplemacOS X Server Version10.4.2
   ApplemacOS X Server Version10.4.3
   ApplemacOS X Server Version10.4.4
   ApplemacOS X Server Version10.4.5
   ApplemacOS X Server Version10.4.6
   ApplemacOS X Server Version10.4.7
   ApplemacOS X Server Version10.4.8
   ApplemacOS X Server Version10.4.9
   ApplemacOS X Server Version10.4.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.69% 0.868
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P