CVE-2006-4965
published 2006-09-25CVE-2006-4965: Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
12.38%
95.8th percentile
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.1.5 | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| mozilla | firefox | <= 2.0.0.6 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v7j6-cjp7-gqh6: Argument injection vulnerability in Apple QuickTime 7
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-4673 [MEDIUM] CWE-78 GHSA-v7j6-cjp7-gqh6: Argument injection vulnerability in Apple QuickTime 7
Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.
GHSA
GHSA-8x7f-x5pj-6mmh: Apple QuickTime 7
ghsa_unreviewed·2022-05-01
CVE-2006-4965 [MEDIUM] CWE-94 GHSA-8x7f-x5pj-6mmh: Apple QuickTime 7
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.
GHSA
GHSA-6x5g-m8wv-w9v6: Argument injection vulnerability in Apple QuickTime 7
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-5045 [MEDIUM] CWE-94 GHSA-6x5g-m8wv-w9v6: Argument injection vulnerability in Apple QuickTime 7
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
Red Hat
CVE-2007-5045: Argument injection vulnerability in Apple QuickTime 7
vendor_redhat·CVSS 5.0
CVE-2007-5045 [MEDIUM] CVE-2007-5045: Argument injection vulnerability in Apple QuickTime 7
Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.
Statement: Not vulnerable. These issues did not affect the versions of Firefox as shipped with Red Hat Enterprise Linux.
No detection rules found.
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=305149http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.htmlhttp://secunia.com/advisories/22048http://secunia.com/advisories/27414http://securityreason.com/securityalert/1631http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefoxhttp://www.gnucitizen.org/blog/backdooring-mp3-files/http://www.gnucitizen.org/blog/myspace-quicktime-worm-follow-uphttp://www.kb.cert.org/vuls/id/751808http://www.securityfocus.com/archive/1/446750/100/0/threadedhttp://www.securityfocus.com/archive/1/453756/100/0/threadedhttp://www.securityfocus.com/archive/1/479179/100/0/threadedhttp://www.securityfocus.com/bid/20138http://www.securitytracker.com/id?1018687http://www.vupen.com/english/advisories/2007/3155http://docs.info.apple.com/article.html?artnum=305149http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.htmlhttp://secunia.com/advisories/22048http://secunia.com/advisories/27414http://securityreason.com/securityalert/1631http://www.gnucitizen.org/blog/0day-quicktime-pwns-firefoxhttp://www.gnucitizen.org/blog/backdooring-mp3-files/http://www.gnucitizen.org/blog/myspace-quicktime-worm-follow-uphttp://www.kb.cert.org/vuls/id/751808http://www.securityfocus.com/archive/1/446750/100/0/threadedhttp://www.securityfocus.com/archive/1/453756/100/0/threadedhttp://www.securityfocus.com/archive/1/479179/100/0/threadedhttp://www.securityfocus.com/bid/20138http://www.securitytracker.com/id?1018687http://www.vupen.com/english/advisories/2007/3155
2006-09-25
Published