← Vulnerability feed

Vulnerability record · CVE-2007-4676 · published 7 November 2007

CVE-2007-4676: Apple QuickTime PICT parsing heap buffer overflow allows code execution

Apple · Mac Os X

Apple QuickTime before 7.3 contains a heap-based buffer overflow when parsing PICT images, specifically in the Poly type (0x0070-0x0074) and PackBitsRgn field (0x0099) opcodes. A malformed PICT image can corrupt heap memory, and because QuickTime is widely installed and often processes images automatically, this is a serious remote code execution risk.

9.3 CVSS 2.0 High EPSS 47% · top 1.2% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityAlthough the vulnerability is old and not in KEV, the high CVSS score and very high EPSS percentile indicate significant exploitation potential, and QuickTime remains present in some environments.

What it is

Apple QuickTime before 7.3 contains a heap-based buffer overflow when parsing PICT images, specifically in the Poly type (0x0070-0x0074) and PackBitsRgn field (0x0099) opcodes. A malformed PICT image can corrupt heap memory, and because QuickTime is widely installed and often processes images automatically, this is a serious remote code execution risk.

Impact

A remote attacker can execute arbitrary code with the privileges of the user running QuickTime, leading to full compromise of confidentiality, integrity, and availability. The CVSS 2.0 vector (AV:N/AC:M/Au:N/C:C/I:C/A:C, score 9.3) reflects complete impact without authentication.

Attack surface

The flaw is reached by supplying a crafted PICT image to QuickTime, typically via a web page, email attachment, or file opened by the user. No authentication is required, but some user interaction (opening or viewing the image) is needed per the AC:M vector.

Exploitation

The record is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is 0.46662 (98.8th percentile), indicating a high predicted likelihood of exploitation activity. References include Zero Day Initiative advisories, suggesting coordinated disclosure of a remotely exploitable issue.

What to do

  • Upgrade Apple QuickTime to version 7.3 or later, which contains the fix per the vendor advisory.
  • If QuickTime cannot be updated, disable or remove the PICT image handler and avoid opening untrusted PICT files.
  • Block PICT file attachments and downloads at email and web gateways where feasible.
  • Apply the Microsoft security updates referenced for Windows Vista and Windows XP systems running QuickTime.
  • Restrict user privileges so that successful exploitation does not yield administrative rights.

Detection

  • Monitor for QuickTime or related processes spawning unexpected child processes or making outbound network connections after opening image files.
  • Search endpoint logs for crashes or heap corruption events in QuickTime components when processing PICT files.
  • Inspect email and web proxy logs for PICT attachments or downloads from untrusted sources.
  • Use file inspection or sandboxing to flag malformed PICT files containing Poly (0x0070-0x0074) or PackBitsRgn (0x0099) opcodes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://docs.info.apple.com/article.html?artnum=306896 Vendor Advisory
http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html Vendor Advisory
http://osvdb.org/38546 Broken Link
http://secunia.com/advisories/27523 Third Party Advisory
http://securityreason.com/securityalert/3351 Third Party Advisory
http://www.kb.cert.org/vuls/id/690515 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/483311/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/483313/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/26345 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018894 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-310A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/3723 Third Party Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-066.html Third Party AdvisoryVDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-07-067.html Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38280 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38281 Third Party AdvisoryVDB Entry
http://docs.info.apple.com/article.html?artnum=306896 Vendor Advisory
http://lists.apple.com/archives/Security-announce/2007/Nov/msg00000.html Vendor Advisory
http://osvdb.org/38546 Broken Link
http://secunia.com/advisories/27523 Third Party Advisory
http://securityreason.com/securityalert/3351 Third Party Advisory
http://www.kb.cert.org/vuls/id/690515 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/483311/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/483313/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/26345 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018894 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-310A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/3723 Third Party Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-066.html Third Party AdvisoryVDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-07-067.html Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38280 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/38281 Third Party AdvisoryVDB Entry

Track CVE-2007-4676 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2022-2294Google Chrome WebRTC heap buffer overflow via crafted HTML pageCVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corrupti…KEVEPSS 70%analysed8.8CVE-2021-1789Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Process…KEVEPSS 14%analysed

Source: NIST National Vulnerability Database (record CVE-2007-4676), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.