Format String Vulnerability in Apple iChat by Apple
CVE-2007-0021

Currently unrated

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
23 January 2007

What is CVE-2007-0021?

A format string vulnerability exists in Apple iChat 3.1.6, which can be exploited by remote attackers through manipulated aim:// URIs. By using specific format string specifiers, an attacker can induce a null pointer dereference, leading to application crashes and the potential execution of arbitrary code, compromising the security of the system.

References

EPSS Score

40% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.