PoC Index

CVE-2007-2175

HIGH 7.6EPSS 83.8%

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.

CVSS v2.0
7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
EPSS
83.80% chance of exploitation in the next 30 days, 100th percentile
Published
2007-04-24
Updated
2024-08-07

Metasploit modules (1)

ExploitDB entries (3)

References

Related