ID

VAR-200705-0156


CVE

CVE-2007-0745


TITLE

Apple Security Update 2007-004 Directory access vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2007-001524

DESCRIPTION

The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories. Mac OS X Server is prone to a remote security vulnerability

Trust: 1.98

sources: NVD: CVE-2007-0745 // JVNDB: JVNDB-2007-001524 // BID: 86634 // VULHUB: VHN-24107

AFFECTED PRODUCTS

vendor:applemodel:mac os x serverscope:eqversion:10.4.9

Trust: 2.4

vendor:applemodel:mac os serverscope:eqversion:x10.4.9

Trust: 0.3

sources: BID: 86634 // JVNDB: JVNDB-2007-001524 // CNNVD: CNNVD-200705-023 // NVD: CVE-2007-0745

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-0745
value: HIGH

Trust: 1.0

NVD: CVE-2007-0745
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200705-023
value: HIGH

Trust: 0.6

VULHUB: VHN-24107
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-0745
severity: HIGH
baseScore: 7.1
vectorString: AV:A/AC:L/AU:S/C:C/I:C/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-24107
severity: HIGH
baseScore: 7.1
vectorString: AV:A/AC:L/AU:S/C:C/I:C/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 5.1
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-24107 // JVNDB: JVNDB-2007-001524 // CNNVD: CNNVD-200705-023 // NVD: CVE-2007-0745

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-0745

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-200705-023

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200705-023

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-001524

PATCH

title:APPLE-SA-2007-05-01url:http://lists.apple.com/archives/security-announce/2007/May/msg00000.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-001524

EXTERNAL IDS

db:NVDid:CVE-2007-0745

Trust: 2.8

db:SECTRACKid:1017990

Trust: 2.0

db:OSVDBid:34869

Trust: 1.7

db:XFid:34001

Trust: 0.9

db:JVNDBid:JVNDB-2007-001524

Trust: 0.8

db:APPLEid:APPLE-SA-2007-05-01

Trust: 0.6

db:CNNVDid:CNNVD-200705-023

Trust: 0.6

db:BIDid:86634

Trust: 0.4

db:VULHUBid:VHN-24107

Trust: 0.1

sources: VULHUB: VHN-24107 // BID: 86634 // JVNDB: JVNDB-2007-001524 // CNNVD: CNNVD-200705-023 // NVD: CVE-2007-0745

REFERENCES

url:http://lists.apple.com/archives/security-announce/2007/may/msg00000.html

Trust: 2.0

url:http://www.securitytracker.com/id?1017990

Trust: 2.0

url:http://www.osvdb.org/34869

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/34001

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/34001

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-0745

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-0745

Trust: 0.8

sources: VULHUB: VHN-24107 // BID: 86634 // JVNDB: JVNDB-2007-001524 // CNNVD: CNNVD-200705-023 // NVD: CVE-2007-0745

CREDITS

Unknown

Trust: 0.3

sources: BID: 86634

SOURCES

db:VULHUBid:VHN-24107
db:BIDid:86634
db:JVNDBid:JVNDB-2007-001524
db:CNNVDid:CNNVD-200705-023
db:NVDid:CVE-2007-0745

LAST UPDATE DATE

2025-04-10T23:21:01.263000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-24107date:2017-07-29T00:00:00
db:BIDid:86634date:2007-05-02T00:00:00
db:JVNDBid:JVNDB-2007-001524date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200705-023date:2007-05-03T00:00:00
db:NVDid:CVE-2007-0745date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-24107date:2007-05-02T00:00:00
db:BIDid:86634date:2007-05-02T00:00:00
db:JVNDBid:JVNDB-2007-001524date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200705-023date:2007-05-02T00:00:00
db:NVDid:CVE-2007-0745date:2007-05-02T21:19:00