CVE-2007-0646
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
- Apple Imovie
- = 6.0.3
- Apple Safari
- All versions
- Apple Mac Os X
- = 10.3.9
- Fix
- Available
- CVSS 2.0
- 7.1 HIGH
- EPSS
- 9.9% (95th percentile)
- Weakness
- CWE-134
- NVD status
- Modified
- Published
- 2007-02-01
CVE-2007-0646 at NVD
1 known exploit for CVE-2007-0646
Proof-of-concept code and exploit modules indexed by Sploitus