7.1
CVSSv2

CVE-2007-0644

Published: 01/02/2007 Updated: 05/09/2008
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted malicious users to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 2.0.4_419.3

Exploits

source: wwwsecurityfocuscom/bid/22326/info Multiple products for Mac OS X are prone to multiple remote format-string vulnerabilities The affected applications include Help Viewer, Safari, iPhoto, and iMovie Exploiting these issues can allow attacker-supplied data to be written to arbitrary memory locations, which can facilitate t ...