CVE-2007-3746: Medium severity Apple iOS and macOS vulnerability
Published Aug 3, 2007
·Updated
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.
Affected Software
42 affected components
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple iOS and macOS=10.3.7
Apple iOS and macOS=10.3.8
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.1
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.3.4
Apple Mac OS X Server=10.3.5
Apple Mac OS X Server=10.3.6
Apple Mac OS X Server=10.3.7
Apple Mac OS X Server=10.3.8
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.7
Apple Mac OS X Server=10.4.8
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.4.10
Apple iChat
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 3, 2007
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:17 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2007-3746?
CVE-2007-3746 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2007-3746?
The recommended action to mitigate CVE-2007-3746 is to update the affected software to a patched version provided by Apple.
3
What systems are affected by CVE-2007-3746?
CVE-2007-3746 affects Apple Mac OS X versions 10.3.9 and 10.4.10.
4
Can CVE-2007-3746 be exploited remotely?
Yes, CVE-2007-3746 can be exploited remotely through a crafted Java applet.
5
What are the impacts of CVE-2007-3746?
Exploitation of CVE-2007-3746 can lead to arbitrary code execution on the vulnerable system.