7.1
CVSSv2

CVE-2007-0646

Published: 01/02/2007 Updated: 07/03/2011
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 up to and including 10.4.10, allows remote user-assisted malicious users to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.

Vulnerable Product Search on Vulmon Subscribe to Product

apple imovie 6.0.3

apple mac_os_x 10.3.9

apple safari

Exploits

source: wwwsecurityfocuscom/bid/22326/info Multiple products for Mac OS X are prone to multiple remote format-string vulnerabilities The affected applications include Help Viewer, Safari, iPhoto, and iMovie Exploiting these issues can allow attacker-supplied data to be written to arbitrary memory locations, which can facilitate the exe ...