{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-15T18:20:34.987","vulnerabilities":[{"cve":{"id":"CVE-2007-5045","sourceIdentifier":"cve@mitre.org","published":"2007-09-24T00:17:00.000","lastModified":"2026-04-23T00:35:47.467","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox \"-chrome\" argument.  NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670."},{"lang":"es","value":"Vulnerabilidad de inyección de argumentos en Apple QuickTime 7.1.5 y anteriores, cuando se ejecutan en sistemas con Mozilla Firefox anterior a 2.0.0.7 instalado, permite a atacantes remotos ejecutar comandos de su elección mediante un archivo de Enlace a Medios QuickTime (QuickTime Media Link o QTL) con un elemento XML embed y un parámetro qtnext que contiene el argumento de Firefox \"-chrome\". NOTA: este es un problema relacionado con CVE-2006-4965 y el resultado de un arreglo incompleto para CVE-2007-3670."}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1.5","matchCriteriaId":"1A83BA45-8718-4C90-947C-7B228559F81C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.0.6","matchCriteriaId":"67F139F7-1344-4EE5-B6A4-ED2653B8875A"}]}]}],"references":[{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742","source":"cve@mitre.org"},{"url":"http://secunia.com/advisories/26881","source":"cve@mitre.org","tags":["Patch","Vendor Advisory"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1","source":"cve@mitre.org"},{"url":"http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox","source":"cve@mitre.org"},{"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-28.html","source":"cve@mitre.org","tags":["Patch"]},{"url":"http://www.novell.com/linux/security/advisories/2007_57_mozilla.html","source":"cve@mitre.org"},{"url":"http://www.securityfocus.com/archive/1/479179/100/0/threaded","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2007/3197","source":"cve@mitre.org"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=395942","source":"cve@mitre.org"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5896","source":"cve@mitre.org"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/26881","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefox","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-28.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"http://www.novell.com/linux/security/advisories/2007_57_mozilla.html","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/archive/1/479179/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2007/3197","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=395942","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5896","source":"af854a3a-2127-422b-91ae-364da2661108"}],"vendorComments":[{"organization":"Red Hat","comment":"Not vulnerable. These issues did not affect the versions of Firefox as shipped with Red Hat Enterprise Linux.","lastModified":"2007-10-04T00:00:00"}]}}]}