9.3
CVSSv2

CVE-2014-1243

Published: 27/02/2014 Updated: 27/02/2014
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Apple QuickTime prior to 7.7.5 does not initialize an unspecified pointer, which allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via a crafted track list in a movie file.

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime 7.0.0

apple quicktime 7.0.1

apple quicktime 7.0.2

apple quicktime 7.0.3

apple quicktime 7.0.4

apple quicktime 7.4.0

apple quicktime 7.4.1

apple quicktime 7.4.5

apple quicktime 7.5.0

apple quicktime 7.66.71.0

apple quicktime 7.67.75.0

apple quicktime 7.68.75.0

apple quicktime 7.69.80.9

apple quicktime

apple quicktime 7.1.1

apple quicktime 7.1.3

apple quicktime 7.2.1

apple quicktime 7.3.1

apple quicktime 7.6.0

apple quicktime 7.6.2

apple quicktime 7.62.14.0

apple quicktime 7.65.17.80

apple quicktime 7.7.0

apple quicktime 7.7.2

apple quicktime 7.1.4

apple quicktime 7.1.5

apple quicktime 7.1.6

apple quicktime 7.2.0

apple quicktime 7.6.5

apple quicktime 7.6.6

apple quicktime 7.6.7

apple quicktime 7.6.8

apple quicktime 7.6.9

apple quicktime 7.70.80.34

apple quicktime 7.71.80.42

apple quicktime 7.1.0

apple quicktime 7.1.2

apple quicktime 7.3.0

apple quicktime 7.3.1.70

apple quicktime 7.5.5

apple quicktime 7.6.1

apple quicktime 7.60.92.0

apple quicktime 7.64.17.73

apple quicktime 7.7.1

apple quicktime 7.7.3

Vendor Advisories

Debian Bug report logs - #734745 graphviz: Multiple security issues Package: graphviz; Maintainer for graphviz is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for graphviz is src:graphviz (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 9 Jan 2014 14:15:01 UTC Severity: grave T ...