{"api_version":"1","generated_at":"2026-07-23T06:05:38+00:00","cve":"CVE-2007-0059","urls":{"html":"https://cve.report/CVE-2007-0059","api":"https://cve.report/api/cve/CVE-2007-0059.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0059","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0059"},"summary":{"title":"CVE-2007-0059","description":"Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-05 00:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/31164","name":"http://osvdb.org/31164","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/304064","name":"http://www.kb.cert.org/vuls/id/304064","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://projects.info-pull.com/moab/MOAB-03-01-2007.html","name":"http://projects.info-pull.com/moab/MOAB-03-01-2007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"MOAB-03-01-2007: Apple Quicktime HREFTrack Cross-Zone Scripting vulnerability","mime":"text/html","httpstatus":"522","archivestatus":"200"},{"url":"http://www.gnucitizen.org/blog/backdooring-quicktime-movies/","name":"http://www.gnucitizen.org/blog/backdooring-quicktime-movies/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Backdooring QuickTime Movies","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html","name":"http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2007-03-05 QuickTime 7.1.5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=305149","name":"http://docs.info.apple.com/article.html?artnum=305149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of QuickTime 7.1.5","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0059","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0059","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"59","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"quicktime","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"59","vulnerable":"1","versionEndIncluding":"7.1.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"quicktime","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-0059","organization":"Apple","lastmodified":"2007-03-19","contributor":"Ron Dumont","statementText":"This issue is addressed in QuickTime 7.1.5, which was released on March 5. Information on the security fixes provided in QuickTime 7.1.5, and links to obtain the update are provided in: http://docs.info.apple.com/article.html?artnum=305149","cve_year":"2007","cve_id":"59","crc32":"bfab3b73"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:03:36.981Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#304064","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/304064"},{"name":"31164","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/31164"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.gnucitizen.org/blog/backdooring-quicktime-movies/"},{"name":"APPLE-SA-2007-03-05","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://projects.info-pull.com/moab/MOAB-03-01-2007.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=305149"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-01-17T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"VU#304064","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/304064"},{"name":"31164","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/31164"},{"tags":["x_refsource_MISC"],"url":"http://www.gnucitizen.org/blog/backdooring-quicktime-movies/"},{"name":"APPLE-SA-2007-03-05","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html"},{"tags":["x_refsource_MISC"],"url":"http://projects.info-pull.com/moab/MOAB-03-01-2007.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=305149"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0059","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#304064","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/304064"},{"name":"31164","refsource":"OSVDB","url":"http://osvdb.org/31164"},{"name":"http://www.gnucitizen.org/blog/backdooring-quicktime-movies/","refsource":"MISC","url":"http://www.gnucitizen.org/blog/backdooring-quicktime-movies/"},{"name":"APPLE-SA-2007-03-05","refsource":"APPLE","url":"http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html"},{"name":"http://projects.info-pull.com/moab/MOAB-03-01-2007.html","refsource":"MISC","url":"http://projects.info-pull.com/moab/MOAB-03-01-2007.html"},{"name":"http://docs.info.apple.com/article.html?artnum=305149","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=305149"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0059","datePublished":"2007-01-05T00:00:00.000Z","dateReserved":"2007-01-04T00:00:00.000Z","dateUpdated":"2024-08-07T12:03:36.981Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-05 00:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1.3","matchCriteriaId":"B57D423B-5763-45AA-899F-09A553E962BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:apple:quicktime:3.0:*:*:*:*:*:*:*","matchCriteriaId":"D8F310A8-F760-4059-987D-42369F360DE4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"59","Ordinal":"1","Title":"CVE-2007-0059","CVE":"CVE-2007-0059","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"59","Ordinal":"1","NoteData":"Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.","Type":"Description","Title":"CVE-2007-0059"},{"CveYear":"2007","CveId":"59","Ordinal":"2","NoteData":"2007-01-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"59","Ordinal":"3","NoteData":"2007-01-17","Type":"Other","Title":"Modified"}]}}}