cbcvebase.
CVE-2007-2388
published 2007-05-29

CVE-2007-2388: Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code…

PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.97%
92.5th percentile
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.

Affected

1 ranges
VendorProductVersion rangeFixed in
applequicktime
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.