9.3
CVSSv2

CVE-2011-0257

Published: 15/08/2011 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in Apple QuickTime prior to 7.7 allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime

apple quicktime 7.6.1

apple quicktime 7.66.71.0

apple quicktime 7.5.5

apple quicktime 7.3.1.70

apple quicktime 7.2.0

apple quicktime 7.1.5

apple quicktime 7.1.6

apple quicktime 7.6.6

apple quicktime 7.67.75.0

apple quicktime 7.3.0

apple quicktime 7.3.1

apple quicktime 7.1.3

apple quicktime 7.1.4

apple quicktime 7.6.8

apple quicktime 7.6.5

apple quicktime 7.4.1

apple quicktime 7.4.5

apple quicktime 7.1.1

apple quicktime 7.1.2

apple quicktime 7.0.3

apple quicktime 7.0.4

apple quicktime 7.6.0

apple quicktime 7.6.7

apple quicktime 7.6.2

apple quicktime 7.5.0

apple quicktime 7.4.0

apple quicktime 7.2.1

apple quicktime 7.1.0

apple quicktime 7.0.0

apple quicktime 7.0.1

apple quicktime 7.0.2

Exploits

## # $Id: apple_quicktime_pnsizerb 13691 2011-09-03 21:17:58Z mc $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' c ...
This Metasploit module exploits a vulnerability in Apple QuickTime Player 760920 When opening a mov file containing a specially crafted PnSize value, an attacker may be able to execute arbitrary code ...
This Metasploit module exploits a vulnerability in QQPLAYER Player 32 When opening a mov file containing a specially crafted PnSize value, an attacker may be able to execute arbitrary code ...