CVE-2007-3747: Medium severity Apple iOS and macOS vulnerability
Published Aug 3, 2007
·Updated
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.
Affected Software
42 affected components
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple iOS and macOS=10.3.7
Apple iOS and macOS=10.3.8
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.1
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.3.4
Apple Mac OS X Server=10.3.5
Apple Mac OS X Server=10.3.6
Apple Mac OS X Server=10.3.7
Apple Mac OS X Server=10.3.8
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.7
Apple Mac OS X Server=10.4.8
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.4.10
Apple iChat
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 3, 2007
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:17 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2007-3747?
CVE-2007-3747 is considered critical due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2007-3747?
To fix CVE-2007-3747, users should update their Mac OS X to the latest version available from Apple that addresses this vulnerability.
3
Which versions of Mac OS X are affected by CVE-2007-3747?
CVE-2007-3747 affects Mac OS X 10.3.9 and 10.4.10, among other versions.
4
Can CVE-2007-3747 be exploited through a web applet?
Yes, CVE-2007-3747 can be exploited via a crafted applet that allows remote code execution.
5
What are the potential impacts of CVE-2007-3747 on my system?
The potential impacts of CVE-2007-3747 include unauthorized access, data loss, and complete system compromise.