CVE-2007-2175

N/A Unknown
Published: April 24, 2007 Modified: April 23, 2026
View on NVD

Description

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.kb.cert.org/vuls/id/420668
Source: cve@mitre.org
US Government Resource
http://www.osvdb.org/34178
Source: cve@mitre.org
http://docs.info.apple.com/article.html?artnum=305446
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.kb.cert.org/vuls/id/420668
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.osvdb.org/34178
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/467319/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1017950
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.theregister.co.uk/2007/04/20/pwn-2-own_winner/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.zerodayinitiative.com/advisories/ZDI-07-023.html
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/33827
Source: af854a3a-2127-422b-91ae-364da2661108

24 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
85.3%
99th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

apple