VulnerabilityModified
CVE-2007-3751
Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.
HIGH 9.3EPSS 25.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java applets that gain privileges via unspecified vectors.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 25.66% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x · microsoft/windows vista · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=306896Vendor Advisory
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.htmlPatch, Vendor Advisory
- http://osvdb.org/38548Broken Link
- http://secunia.com/advisories/27523Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/319771Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/26339Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018894Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-310A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3723Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38271Third Party Advisory, VDB Entry
- http://docs.info.apple.com/article.html?artnum=306896Vendor Advisory
- http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.htmlPatch, Vendor Advisory
- http://osvdb.org/38548Broken Link
- http://secunia.com/advisories/27523Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/319771Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/26339Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018894Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-310A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3723Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38271Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.