← Vulnerability feed

Vulnerability record · CVE-2007-6165 · published 29 November 2007

CVE-2007-6165: Apple Mac OS X Mail AppleDouble attachment code execution

Apple · Mac Os X

Apple Mail in Mac OS X Leopard 10.5.1 fails to warn users when an AppleDouble attachment with an apparently safe file type hides an executable script in its resource fork. Opening such an attachment can run a separate program without the user's knowledge. This is a regression of CVE-2006-0395.

9.3 CVSS 2.0 High EPSS 45% · top 1.3% CWE-20 · Improper input validationCWE-264 · Permissions and access controls
9.3CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution with no authentication and a public exploit reference, though it requires the user to open an attachment and affects an old OS version.

What it is

Apple Mail in Mac OS X Leopard 10.5.1 fails to warn users when an AppleDouble attachment with an apparently safe file type hides an executable script in its resource fork. Opening such an attachment can run a separate program without the user's knowledge. This is a regression of CVE-2006-0395.

Impact

An attacker can execute arbitrary code with the privileges of the user who opens the attachment. Because the file appears safe, the user is unlikely to suspect anything until after execution.

Attack surface

Reached remotely by sending an email with a crafted AppleDouble attachment; no authentication is required, but the victim must open the attachment (user interaction). The CVSS vector AV:N/AC:M/Au:N confirms network delivery and medium attack complexity.

Exploitation

Not listed in CISA KEV. EPSS is 0.44746 (98.7th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit information exists.

What to do

  • Apply the Apple security update referenced in Apple advisory 307179 and US-CERT alert TA07-352A.
  • Upgrade from Mac OS X 10.5.1 to a patched release.
  • Disable automatic opening of attachments in Mail and train users not to open unexpected AppleDouble attachments.
  • Block or strip AppleDouble resource-fork attachments at the email gateway where feasible.

Detection

  • Search mail logs and quarantine for AppleDouble attachments containing resource forks or executable content.
  • Monitor for unexpected child processes spawned by Mail.
  • Alert on email attachments whose declared type differs from the content in the resource fork.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6165 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2022-2294Google Chrome WebRTC heap buffer overflow via crafted HTML pageCVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corrupti…KEVEPSS 70%analysed8.8CVE-2021-1789Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Process…KEVEPSS 14%analysed7.8CVE-2021-30713Apple macOS privacy preference bypass via missing authorizationmacOS Big Sur before 11.4 has a permissions validation flaw (CWE-862 missing authorization) that lets a malicious application bypass Privacy preferen…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2007-6165), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.