CVE Feed

    Dashboard / CVE / CVE-2007-5045

    CVE-2007-5045

    Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.

    Published:Sep 24, 2007
    Last Modified:Apr 23, 2026
    EPS:Sep 24, 2007
    EPSS Score:0.02046
    CVSS Score:9.3

    Affected Products

    Vendor
    Apple
    Product
    Quicktime
    Vendor
    Mozilla
    Product
    Firefox

    Exploits

    No exploit reference

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High