9.3
CVSSv2

CVE-2008-5406

Published: 10/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."

Vulnerable Product Search on Vulmon Subscribe to Product

apple itunes 8.0.2.20

apple quicktime 7.5.5

Exploits

--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Quicktime/Itunes Multiple Remote Off By One Overflow Application: Itunes 80220/Quicktime 755 (24926)(-> ver ...