cbcvebase.
CVE-2004-0431
published 2004-07-07

CVE-2004-0431: Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the…

PriorityP266medium5.1CVSS 2.0
AVNACHAuNCPIPAP
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.24%
86.9th percentile
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.

Affected

1 ranges
VendorProductVersion rangeFixed in
applequicktime<= 6.5

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck5.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.