CVE-2007-0647
macOS Help Viewer 3.0.0 - Denial of Service via Format String in Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0647. PoCs published by LMH.
AI-analyzed exploit summary This exploit leverages a format-string vulnerability in multiple Mac OS X applications (Help Viewer, Safari, iPhoto, iMovie) by creating a maliciously named file that triggers arbitrary memory writes when opened, potentially leading to remote code execution.
Description
Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.
Exploits (1)
This exploit leverages a format-string vulnerability in multiple Mac OS X applications (Help Viewer, Safari, iPhoto, iMovie) by creating a maliciously named file that triggers arbitrary memory writes when opened, potentially leading to remote code execution.