CVE-2007-3744 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple MAC OS X
Severity
5.8MEDIUMNVD
EPSS
6.6%
top 8.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 3
Latest updateMay 1
Description
Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
CVSS vector
AV:A/AC:L/C:P/I:P/A:PExploitability: 6.5 | Impact: 6.4
Affected Packages2 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-c4f5-524q-wgpg: Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac↗2022-05-01