peter bassill · operator
$ cve CVE-2007-0644 JSON

CVE-2007-0644 EXPLOIT

7.1
HIGH · CVSS 2.0 · EPSS 2.5% (pctl 85)

Patch early

A public exploit exists.

Description

Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.

Scoring

CVSS7.1 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
EPSS2.55% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2007-02-01
Last modified2026-06-16

Affected (1)

VendorProduct
applesafari

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD