CVE-2007-0646: High severity Apple iOS and macOS vulnerability
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0646?
CVE-2007-0646 has a severity rating that indicates it can lead to a denial of service via a crash.
How do I fix CVE-2007-0646?
To fix CVE-2007-0646, users should update to newer versions of iMovie and Safari that do not have this vulnerability.
What versions of Apple software are affected by CVE-2007-0646?
CVE-2007-0646 affects iMovie HD 6.0.3 and Safari on Mac OS X versions 10.4 through 10.4.10.
Can CVE-2007-0646 be exploited remotely?
CVE-2007-0646 requires user-assisted exploitation, meaning the attack must be initiated by the user.
Is iMovie version 6.0.4 vulnerable to CVE-2007-0646?
No, iMovie version 6.0.4 is not affected by CVE-2007-0646 as it was released after the vulnerability was identified.