CVE-2008-0033Out-of-bounds Write in Apple Quicktime

CWE-3994 documents4 sources
Severity
9.3CRITICALNVD
EPSS
30.6%
top 3.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16
Latest updateMay 1

Description

Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/quicktime7.3.1.70

🔴Vulnerability Details

2
GHSA
GHSA-p63g-j95c-8cvh: Unspecified vulnerability in Apple QuickTime before 72022-05-01
CVEList
CVE-2008-0033: Unspecified vulnerability in Apple QuickTime before 72008-01-16

💬Community

1
Bugzilla
CVE-2009-0033 CVE-2009-0580 CVE-2009-0783 CVE-2008-5515 CVE-2009-0781 Multiple tomcat5 vulnerabilities [Fedora all]2009-11-09
CVE-2008-0033 — Out-of-bounds Write in Apple Quicktime | cvebase