CVE-2007-0588 is a denial-of-service and potential arbitrary code execution vulnerability affecting Apple QuickTime 7.1.3 and earlier, and Mac OS X 10.4.8 and earlier. It stems from memory corruption in the QuickDraw InternalUnpackBits function, triggered by a specially crafted PICT file. With a CVSS score of 7.1, this vulnerability is remotely exploitable with medium attack complexity, leading to an application crash and potentially arbitrary code execution. While its FAUCET Risk Score is high at 92/100, there is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not currently a high-profile threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1.3CPE matchmatch criteria | cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:* | ||
10.4.8CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.