← Vulnerability feed

Vulnerability record · CVE-2007-0748 · published 13 May 2007

CVE-2007-0748: Apple darwin streaming server vulnerability

Apple · Darwin Streaming Server

Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request.

10.0 CVSS 2.0 High EPSS 6.5% · top 6.5%
10.0CVSS 2.0 base score
6.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allows remote attackers to execute arbitrary code via multiple trackID values in a SETUP RTSP request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-0748 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-0749Apple darwin streaming server vulnerabilityMultiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server befor…EPSS 6.5%10.0CVE-2003-0421Apple darwin streaming server vulnerabilityApple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. …EPSS 2.9%10.0CVE-2003-0426Apple darwin streaming server vulnerabilityThe installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allow…EPSS 3.4%10.0CVE-2003-0502Apple darwin streaming server vulnerabilityApple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence foll…EPSS 3.4%7.5CVE-2004-1083Apple darwin streaming server vulnerabilityApache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a c…EPSS 1.9%7.5CVE-2004-1086Apple darwin streaming server vulnerabilityBuffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.EPSS 3.4%7.5CVE-2004-1088Apple darwin streaming server vulnerabilityPostfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authenticatio…EPSS 1.7%7.5CVE-2003-0050Apple Streaming Server CGI shell metacharacter code executionparse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 passes input to a shell without sanitizing s…EPSS 69%analysed

Source: NIST National Vulnerability Database (record CVE-2007-0748), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.