Vulnerability Details CVE-2006-2238
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.38
EPSS Ranking 97.1%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-2238
-
cpe:2.3:a:apple:quicktime:-
-
cpe:2.3:a:apple:quicktime:3
-
cpe:2.3:a:apple:quicktime:3.0
-
cpe:2.3:a:apple:quicktime:4.1.2
-
cpe:2.3:a:apple:quicktime:5.0
-
cpe:2.3:a:apple:quicktime:5.0.1
-
cpe:2.3:a:apple:quicktime:5.0.2
-
cpe:2.3:a:apple:quicktime:6.0
-
cpe:2.3:a:apple:quicktime:6.0.0
-
cpe:2.3:a:apple:quicktime:6.0.1
-
cpe:2.3:a:apple:quicktime:6.0.2
-
cpe:2.3:a:apple:quicktime:6.1
-
cpe:2.3:a:apple:quicktime:6.1.0
-
cpe:2.3:a:apple:quicktime:6.1.1
-
cpe:2.3:a:apple:quicktime:6.2.0
-
cpe:2.3:a:apple:quicktime:6.3.0
-
cpe:2.3:a:apple:quicktime:6.4.0
-
cpe:2.3:a:apple:quicktime:6.5
-
cpe:2.3:a:apple:quicktime:6.5.0
-
cpe:2.3:a:apple:quicktime:6.5.1
-
cpe:2.3:a:apple:quicktime:6.5.2
-
cpe:2.3:a:apple:quicktime:7.0
-
cpe:2.3:a:apple:quicktime:7.0.0
-
cpe:2.3:a:apple:quicktime:7.0.1
-
cpe:2.3:a:apple:quicktime:7.0.2
-
cpe:2.3:a:apple:quicktime:7.0.3
-
cpe:2.3:a:apple:quicktime:7.0.4