CVE-2007-2393
Summary
| CVE | CVE-2007-2393 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-15 21:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution. |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Quicktime | - | All | All | All |
| Application | Apple | Quicktime | 7.0 | All | All | All |
| Application | Apple | Quicktime | 7.0.1 | All | All | All |
| Application | Apple | Quicktime | 7.0.2 | All | All | All |
| Application | Apple | Quicktime | 7.0.3 | All | All | All |
| Application | Apple | Quicktime | 7.0.4 | All | All | All |
| Application | Apple | Quicktime | 7.1 | All | All | All |
| Application | Apple | Quicktime | 7.1.1 | All | All | All |
| Application | Apple | Quicktime | 7.1.2 | All | All | All |
| Application | Apple | Quicktime | 7.1.3 | All | All | All |
| Application | Apple | Quicktime | 7.1.4 | All | All | All |
| Application | Apple | Quicktime | 7.1.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple QuickTime Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA07-193A -- Apple Releases Security Updates for QuickTime | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| About the security content of QuickTime 7.2 | af854a3a-2127-422b-91ae-364da2661108 | docs.info.apple.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - QuickTime Memory Corruption Bugs Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Apple QuickTime Information Disclosure and Multiple Code Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| APPLE-SA-2007-07-11 QuickTime 7.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch |
| osvdb.org/36135 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.