CVE-2007-0344 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 6.6% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 6.61% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-01-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| colloquy | colloquy |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Colloquy 2.1.3545 - 'INVITE' Format String Denial of Service | 2007-01-17 |
References
- http://projects.info-pull.com/moab/MOAB-16-01-2007.html
- http://secunia.com/advisories/23801
- http://www.osvdb.org/32688
- http://www.securityfocus.com/bid/22086
- http://www.vupen.com/english/advisories/2007/0238
- https://www.exploit-db.com/exploits/3139
- http://projects.info-pull.com/moab/MOAB-16-01-2007.html
- http://secunia.com/advisories/23801
- http://www.osvdb.org/32688
- http://www.securityfocus.com/bid/22086
- http://www.vupen.com/english/advisories/2007/0238
- https://www.exploit-db.com/exploits/3139
→ the Explorer · watch your stack · NVD