{"api_version":"1","generated_at":"2026-07-23T08:14:16+00:00","cve":"CVE-2007-4702","urls":{"html":"https://cve.report/CVE-2007-4702","api":"https://cve.report/api/cve/CVE-2007-4702.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4702","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4702"},"summary":{"title":"CVE-2007-4702","description":"The Application Firewall in Apple Mac OS X 10.5, when \"Block all incoming connections\" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-15 20:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2007/3897","name":"http://www.vupen.com/english/advisories/2007/3897","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27695","name":"http://secunia.com/advisories/27695","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apple Mac OS X Application Firewall Weaknesses and Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html","name":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"APPLE-SA-2007-11-15 Mac OS X v10.5.1 Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38506","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38506","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1018958","name":"http://securitytracker.com/id?1018958","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Mac OS X Application Firewall Bugs May Let Remote Users Access the Services on the Target System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=307004","name":"http://docs.info.apple.com/article.html?artnum=307004","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of the Mac OS X 10.5.1 Update (client and server)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26461","name":"http://www.securityfocus.com/bid/26461","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X 10.5 Application Firewall Misleading Configuration Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4702","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4702","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4702","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4702","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:08:32.957Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27695","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27695"},{"name":"APPLE-SA-2007-11-15","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html"},{"name":"ADV-2007-3897","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3897"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=307004"},{"name":"26461","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26461"},{"name":"1018958","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1018958"},{"name":"macosx-appfw-connect-bypass(38506)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38506"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Application Firewall in Apple Mac OS X 10.5, when \"Block all incoming connections\" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27695","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27695"},{"name":"APPLE-SA-2007-11-15","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html"},{"name":"ADV-2007-3897","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3897"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=307004"},{"name":"26461","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26461"},{"name":"1018958","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1018958"},{"name":"macosx-appfw-connect-bypass(38506)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38506"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4702","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Application Firewall in Apple Mac OS X 10.5, when \"Block all incoming connections\" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27695","refsource":"SECUNIA","url":"http://secunia.com/advisories/27695"},{"name":"APPLE-SA-2007-11-15","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html"},{"name":"ADV-2007-3897","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3897"},{"name":"http://docs.info.apple.com/article.html?artnum=307004","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=307004"},{"name":"26461","refsource":"BID","url":"http://www.securityfocus.com/bid/26461"},{"name":"1018958","refsource":"SECTRACK","url":"http://securitytracker.com/id?1018958"},{"name":"macosx-appfw-connect-bypass(38506)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38506"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4702","datePublished":"2007-11-15T20:00:00.000Z","dateReserved":"2007-09-05T00:00:00.000Z","dateUpdated":"2024-08-07T15:08:32.957Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-15 20:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*","matchCriteriaId":"D2442D35-7484-43D8-9077-3FDF63104816"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*","matchCriteriaId":"20E8648C-5469-4280-A581-D4A9A41B7213"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4702","Ordinal":"1","Title":"CVE-2007-4702","CVE":"CVE-2007-4702","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4702","Ordinal":"1","NoteData":"The Application Firewall in Apple Mac OS X 10.5, when \"Block all incoming connections\" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.","Type":"Description","Title":"CVE-2007-4702"},{"CveYear":"2007","CveId":"4702","Ordinal":"2","NoteData":"2007-11-15","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4702","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}