Vulnerabilities > CVE-2007-0644 - Products Format String vulnerability in Apple Safari 2.0.4419.3

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
apple
exploit available

Summary

Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.

Vulnerable Configurations

Part Description Count
Application
Apple
1

Exploit-Db

descriptionApple Mac OS X 10.4.x Safari window.console.log Format String. CVE-2007-0644. Dos exploit for osx platform
idEDB-ID:29555
last seen2016-02-03
modified2007-01-30
published2007-01-30
reporterLMH
sourcehttps://www.exploit-db.com/download/29555/
titleApple Mac OS X 10.4.x Safari window.console.log Format String