Vulnerabilities
Vulnerable Software
Apple:  >> Quicktime  >> 5.0.2  Security Vulnerabilities
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a GIF image file with a crafted Netscape Navigator Application Extension Block that modifies the heap in the Picture Modifier block.
CVSS Score
7.5
EPSS Score
0.397
Published
2005-12-31
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
CVSS Score
5.1
EPSS Score
0.014
Published
2005-11-05
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
CVSS Score
5.1
EPSS Score
0.014
Published
2005-11-05
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
CVSS Score
2.6
EPSS Score
0.014
Published
2005-11-05
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
CVSS Score
5.1
EPSS Score
0.023
Published
2005-11-05
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.
CVSS Score
5.0
EPSS Score
0.007
Published
2005-03-01
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
CVSS Score
7.5
EPSS Score
0.004
Published
2005-01-27
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
CVSS Score
5.0
EPSS Score
0.003
Published
2005-01-27
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
CVSS Score
5.1
EPSS Score
0.01
Published
2004-07-07
Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field.
CVSS Score
7.5
EPSS Score
0.038
Published
2002-09-24


Contact Us

Shodan ® - All rights reserved