Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-2388
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-2388

Description:
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.

CVE Status:
Candidate

References:

ST
  1018136

SAID
  Secunia Advisory: SA25130

OSVDB
  35576

MISC
  http://secunia.com/secunia_research/2007-52/advisory/

CERT-VN
  995836

BID
  24221

APPLE
  http://lists.apple.com/archives/security-announce/2007/May/msg00005.html


Return to the previous page.