6.8
CVSSv2

CVE-2008-3626

Published: 11/09/2008 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The CallComponentFunctionWithStorage function in Apple QuickTime prior to 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime 5.0.1

apple quicktime 5.0.2

apple quicktime 6.0

apple quicktime 7.0.3

apple quicktime 7.0.4

apple quicktime 7.1.5

apple quicktime 7.1.6

apple quicktime 3.0

apple quicktime

apple quicktime 4.1.2

apple quicktime 5.0

apple quicktime 7.0.1

apple quicktime 7.0.2

apple quicktime 7.1.3

apple quicktime 7.1.4

apple quicktime 7.4

apple quicktime 7.4.4

apple quicktime 6.5.2

apple quicktime 7.0

apple quicktime 7.1.1

apple quicktime 7.1.2

apple quicktime 7.3.1

apple quicktime 7.3.1.70

apple quicktime 6.5

apple quicktime 6.5.1

apple quicktime -

apple quicktime 7.1

apple quicktime 7.2

apple quicktime 7.3