peter bassill · operator
$ cve CVE-2007-0344 JSON

CVE-2007-0344 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 6.6% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS6.61% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2007-01-18
Last modified2026-06-16

Affected (1)

VendorProduct
colloquycolloquy

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD