CVE-2007-2389: High severity Apple iOS and macOS vulnerability
Published May 29, 2007
·Updated
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.
Affected Software
43 affected components
Apple iOS and macOS
Apple iOS and macOS=10.0
Apple iOS and macOS=10.0.1
Apple iOS and macOS=10.0.2
Apple iOS and macOS=10.0.3
Apple iOS and macOS=10.0.4
Apple iOS and macOS=10.1
Apple iOS and macOS=10.1.1
Apple iOS and macOS=10.1.2
Apple iOS and macOS=10.1.3
Apple iOS and macOS=10.1.4
Apple iOS and macOS=10.1.5
Apple iOS and macOS=10.2
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.2.2
Apple iOS and macOS=10.2.3
Apple iOS and macOS=10.2.4
Apple iOS and macOS=10.2.5
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple iOS and macOS=10.3.7
Apple iOS and macOS=10.3.8
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.1
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.9
Microsoft All Windows
Apple QuickTime=7.1.6
Event History
May 29, 2007
CVE Published
09:30 PM
Data Sourced
09:30 PM
DescriptionWeaknessAffected Software
May 30, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2389?
CVE-2007-2389 has a high severity rating due to its ability to allow remote attackers to read potentially sensitive memory.
2
How do I fix CVE-2007-2389?
To fix CVE-2007-2389, users should upgrade to a secure version of Apple QuickTime that is not affected by this vulnerability.
3
Which versions of Apple QuickTime are affected by CVE-2007-2389?
CVE-2007-2389 affects Apple QuickTime 7.1.6 on both Mac OS X and Windows platforms.
4
Can CVE-2007-2389 be exploited through a web browser?
Yes, CVE-2007-2389 can be exploited through a web browser via malicious Java applets.
5
What are the potential impacts of CVE-2007-2389?
The potential impacts of CVE-2007-2389 include unauthorized access to sensitive information stored in memory.