cbcvebase.
CVE-2005-2340
published 2005-12-31

CVE-2005-2340: Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2)…

PriorityP345high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
25.51%
97.7th percentile
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.

Affected

4 ranges
VendorProductVersion rangeFixed in
applequicktime<= 7.0.3
applequicktime
applequicktime
applequicktime

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/27069.jpg
  • Detect heap-based buffer overflow exploitation attempts via crafted QTIF, PICT, or JPEG image files with anomalously long data fields opened in Apple QuickTime before 7.0.4
  • Monitor QuickTime / PictureViewer process for crashes or abnormal termination when parsing .JPEG or .PICT files, as unsuccessful exploitation will crash the application
  • Flag QuickTime versions 6.4, 6.5, 6.5.2, and 7.0.x (up to 7.0.3) as vulnerable targets; treat any crafted image file delivered to these versions as high-risk
  • ·QuickTime 7.0.4 is listed as the patched version per NVD, but exploitation against 7.0.4 had not been fully ruled out at time of disclosure
  • ·This CVE may overlap with BID 16202 covering multiple QuickTime code execution vulnerabilities; correlate detections accordingly
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.