CVE-2007-0463
MEDIUM 5.0EPSS 17.7%
Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 17.66% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2007-01-29
- Updated
- 2024-08-07