CVE-2008-0032
published 2008-01-16CVE-2008-0032: Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
3.81%
88.9th percentile
Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.3 | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vvhx-649h-h6mq: Apple QuickTime before 7
ghsa_unreviewed·2022-05-01
CVE-2008-0032 [MEDIUM] GHSA-vvhx-649h-h6mq: Apple QuickTime before 7
Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.
Red Hat
CVE-2009-0032: CUPS on Mandriva Linux 2008
vendor_redhat·CVSS 6.9
CVE-2009-0032 [MEDIUM] CVE-2009-0032: CUPS on Mandriva Linux 2008
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.
Statement: Not vulnerable. Red Hat does not ship the vulnerable backend that causes this flaw.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://docs.info.apple.com/article.html?artnum=307301http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=642http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.htmlhttp://secunia.com/advisories/28502http://www.securityfocus.com/bid/27301http://www.securitytracker.com/id?1019221http://www.us-cert.gov/cas/techalerts/TA08-016A.htmlhttp://www.vupen.com/english/advisories/2008/0148https://exchange.xforce.ibmcloud.com/vulnerabilities/39696http://docs.info.apple.com/article.html?artnum=307301http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=642http://lists.apple.com/archives/security-announce/2008/Jan/msg00001.htmlhttp://secunia.com/advisories/28502http://www.securityfocus.com/bid/27301http://www.securitytracker.com/id?1019221http://www.us-cert.gov/cas/techalerts/TA08-016A.htmlhttp://www.vupen.com/english/advisories/2008/0148https://exchange.xforce.ibmcloud.com/vulnerabilities/39696
2008-01-16
Published