← Vulnerability feed

Vulnerability record · CVE-2007-0015 · published 1 January 2007

CVE-2007-0015: Apple QuickTime buffer overflow via long rtsp:// URI

Apple · Quicktime

Apple QuickTime 7.1.3 contains a buffer overflow that is triggered when processing an overly long rtsp:// URI. A remote attacker can deliver a crafted URI to crash the application or execute arbitrary code in the context of the user running QuickTime. The flaw matters because QuickTime is widely deployed and the attack requires no authentication.

6.8 CVSS 2.0 Medium EPSS 49% · top 1.2%
6.8CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityPublic exploit code exists and EPSS is very high, but the CVSS base score is medium and exploitation requires user interaction, making it a high priority for patching rather than critical.

What it is

Apple QuickTime 7.1.3 contains a buffer overflow that is triggered when processing an overly long rtsp:// URI. A remote attacker can deliver a crafted URI to crash the application or execute arbitrary code in the context of the user running QuickTime. The flaw matters because QuickTime is widely deployed and the attack requires no authentication.

Impact

An attacker can execute arbitrary code with the privileges of the QuickTime user, leading to full compromise of the affected host. If the user has administrative rights, the attacker could take complete control of the system.

Attack surface

The vulnerability is reached remotely over the network by supplying a long rtsp:// URI to QuickTime, typically via a web page, email, or other application that invokes the handler. No authentication is required, but some user interaction (such as opening a link or file) is likely needed to trigger the parsing of the URI.

Exploitation

Exploit code is publicly referenced in multiple sources, and EPSS indicates a high probability of exploitation activity (0.48669, 98.8th percentile). The vulnerability is not listed in CISA KEV, but the presence of public exploits and the age of the flaw make exploitation likely in unpatched environments.

What to do

  • Apply the vendor patch from Apple as referenced in the security advisory (Apple Security Announce, Secunia advisory 23540, and US-CERT alert TA07-005A).
  • If patching is not immediately possible, disable or restrict the rtsp:// URI handler for QuickTime, or remove QuickTime if it is not required.
  • Block or filter rtsp:// URIs at email and web gateways where feasible to reduce exposure.
  • Educate users not to open untrusted links or files that may invoke QuickTime.
  • Consider application whitelisting or endpoint controls to prevent QuickTime from launching from untrusted sources.

Detection

  • Monitor for processes spawning QuickTime with unusual command-line arguments containing long rtsp:// strings.
  • Inspect network traffic for rtsp:// URIs with abnormally long or malformed parameters.
  • Review endpoint logs for crashes or exceptions in QuickTime or related components.
  • Use file integrity monitoring to detect unauthorized changes to QuickTime binaries or plugins.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=304989
http://isc.sans.org/diary.html?storyid=2094
http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html
http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html
http://projects.info-pull.com/moab/MOAB-01-01-2007.html Exploit
http://secunia.com/advisories/23540 PatchVendor Advisory
http://secunia.com/blog/7/
http://securitytracker.com/id?1017461 Exploit
http://www.kb.cert.org/vuls/id/442497 PatchUS Government Resource
http://www.osvdb.org/31023
http://www.securityfocus.com/bid/21829 Exploit
http://www.us-cert.gov/cas/techalerts/TA07-005A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0001
https://exchange.xforce.ibmcloud.com/vulnerabilities/31203
https://www.exploit-db.com/exploits/3064
http://docs.info.apple.com/article.html?artnum=304989
http://isc.sans.org/diary.html?storyid=2094
http://landonf.bikemonkey.org/code/macosx/MOAB_Day_1.20070102060815.15950.zadder.local.html
http://lists.apple.com/archives/Security-announce/2007/Jan/msg00000.html
http://projects.info-pull.com/moab/MOAB-01-01-2007.html Exploit
http://secunia.com/advisories/23540 PatchVendor Advisory
http://secunia.com/blog/7/
http://securitytracker.com/id?1017461 Exploit
http://www.kb.cert.org/vuls/id/442497 PatchUS Government Resource
http://www.osvdb.org/31023
http://www.securityfocus.com/bid/21829 Exploit
http://www.us-cert.gov/cas/techalerts/TA07-005A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0001
https://exchange.xforce.ibmcloud.com/vulnerabilities/31203
https://www.exploit-db.com/exploits/3064

Track CVE-2007-0015 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6238Apple quicktime vulnerabilityUnspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably…EPSS 3.9%10.0CVE-2007-0462Apple quicktime vulnerabilityThe _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote at…EPSS 6.7%9.8CVE-2011-3428Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.EPSS 2.0%9.3CVE-2014-4979Apple quicktime memory buffer overflow vulnerabilityApple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and…EPSS 3.6%9.3CVE-2014-1243Apple quicktime memory buffer overflow vulnerabilityApple QuickTime before 7.7.5 does not initialize an unspecified pointer, which allows remote attackers to execute arbitrary code or cause a denial of…EPSS 3.6%9.3CVE-2014-1244Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…EPSS 4.1%9.3CVE-2014-1245Apple quicktime vulnerabilityInteger signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application …EPSS 3.6%9.3CVE-2014-1246Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2007-0015), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.