CVE-2007-2388: Critical severity Apple iOS and macOS vulnerability
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2388?
CVE-2007-2388 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2007-2388?
To fix CVE-2007-2388, users should update to a version of Apple QuickTime that is not affected by this vulnerability.
Which versions of Apple QuickTime are vulnerable to CVE-2007-2388?
Apple QuickTime version 7.1.6 is vulnerable to CVE-2007-2388.
What causes the vulnerability CVE-2007-2388?
CVE-2007-2388 arises from improper restrictions on QTObject subclassing which can be exploited to execute unsafe functions.
Are Mac OS X and Windows affected by CVE-2007-2388?
Yes, both Mac OS X and Windows systems running Apple QuickTime version 7.1.6 are affected by CVE-2007-2388.