CVE-2007-0714Apple Quicktime vulnerability

CWE-1893 documents3 sources
Severity
9.3CRITICALNVD
EPSS
46.7%
top 2.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 5
Latest updateMay 1

Description

Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/quicktime7.1.4+26

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g269-2cm3-p62m: Integer overflow in Apple QuickTime before 72022-05-01
CVEList
CVE-2007-0714: Integer overflow in Apple QuickTime before 72007-03-05
CVE-2007-0714 — Apple Quicktime vulnerability | cvebase