CVE-2007-4677 is a critical heap-based buffer overflow vulnerability in Apple QuickTime versions prior to 7.3, allowing remote attackers to execute arbitrary code by exploiting an invalid color table size within a movie file's CTAB atom. This vulnerability affects Apple QuickTime on various operating systems including macOS and Windows XP/Vista. With a CVSS score of 9.3, it is highly severe, requiring medium attack complexity but enabling complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high EPSS and FAUCET Risk Score indicate a significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.3.9CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:* | ||
10.4.10CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.4.10:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.