{"api_version":"1","generated_at":"2026-07-23T07:31:54+00:00","cve":"CVE-2007-4703","urls":{"html":"https://cve.report/CVE-2007-4703","api":"https://cve.report/api/cve/CVE-2007-4703.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4703","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4703"},"summary":{"title":"CVE-2007-4703","description":"The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when \"Block incoming connections\" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-11-15 20:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38479","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38479","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3897","name":"http://www.vupen.com/english/advisories/2007/3897","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26460","name":"http://www.securityfocus.com/bid/26460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X Application Firewall Unauthorized Network Access Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/27695","name":"http://secunia.com/advisories/27695","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Apple Mac OS X Application Firewall Weaknesses and Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html","name":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"APPLE-SA-2007-11-15 Mac OS X v10.5.1 Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1018958","name":"http://securitytracker.com/id?1018958","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Mac OS X Application Firewall Bugs May Let Remote Users Access the Services on the Target System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=307004","name":"http://docs.info.apple.com/article.html?artnum=307004","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"About the security content of the Mac OS X 10.5.1 Update (client and server)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4703","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4703","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4703","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4703","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:08:32.968Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27695","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27695"},{"name":"APPLE-SA-2007-11-15","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html"},{"name":"macosx-appfw-rootuid-bypass(38479)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38479"},{"name":"26460","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26460"},{"name":"ADV-2007-3897","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3897"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=307004"},{"name":"1018958","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1018958"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when \"Block incoming connections\" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27695","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27695"},{"name":"APPLE-SA-2007-11-15","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html"},{"name":"macosx-appfw-rootuid-bypass(38479)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38479"},{"name":"26460","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26460"},{"name":"ADV-2007-3897","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3897"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=307004"},{"name":"1018958","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1018958"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4703","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when \"Block incoming connections\" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27695","refsource":"SECUNIA","url":"http://secunia.com/advisories/27695"},{"name":"APPLE-SA-2007-11-15","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2007/Nov/msg00004.html"},{"name":"macosx-appfw-rootuid-bypass(38479)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38479"},{"name":"26460","refsource":"BID","url":"http://www.securityfocus.com/bid/26460"},{"name":"ADV-2007-3897","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3897"},{"name":"http://docs.info.apple.com/article.html?artnum=307004","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=307004"},{"name":"1018958","refsource":"SECTRACK","url":"http://securitytracker.com/id?1018958"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4703","datePublished":"2007-11-15T20:00:00.000Z","dateReserved":"2007-09-05T00:00:00.000Z","dateUpdated":"2024-08-07T15:08:32.968Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-11-15 20:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*","matchCriteriaId":"D2442D35-7484-43D8-9077-3FDF63104816"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*","matchCriteriaId":"20E8648C-5469-4280-A581-D4A9A41B7213"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4703","Ordinal":"1","Title":"CVE-2007-4703","CVE":"CVE-2007-4703","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4703","Ordinal":"1","NoteData":"The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when \"Block incoming connections\" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.","Type":"Description","Title":"CVE-2007-4703"},{"CveYear":"2007","CveId":"4703","Ordinal":"2","NoteData":"2007-11-15","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4703","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}