CVE-2008-3615
published 2008-09-11CVE-2008-3615: ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, accesses uninitialized memory…
PriorityP434critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.99%
89.4th percentile
ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, accesses uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | < 7.5.5 | 7.5.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw7j-p4c6-68v7: Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arb
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-4311 [CRITICAL] CWE-94 GHSA-cw7j-p4c6-68v7: Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arb
Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
GHSA
GHSA-c666-x77g-r6w9: ir50_32
ghsa_unreviewed·2022-05-02
CVE-2008-3615 [HIGH] GHSA-c666-x77g-r6w9: ir50_32
ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, accesses uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce//2008/Sep/msg00000.htmlhttp://secunia.com/advisories/31821http://securitytracker.com/id?1020841http://support.apple.com/kb/HT3027http://www.ngssoftware.com/advisories/critical-vulnerability-in-apple-quicktimes-indeo-codec/http://www.securityfocus.com/archive/1/496358/100/0/threadedhttp://www.securityfocus.com/bid/31086http://www.vupen.com/english/advisories/2008/2527http://lists.apple.com/archives/security-announce//2008/Sep/msg00000.htmlhttp://secunia.com/advisories/31821http://securitytracker.com/id?1020841http://support.apple.com/kb/HT3027http://www.ngssoftware.com/advisories/critical-vulnerability-in-apple-quicktimes-indeo-codec/http://www.securityfocus.com/archive/1/496358/100/0/threadedhttp://www.securityfocus.com/bid/31086http://www.vupen.com/english/advisories/2008/2527
2008-09-11
Published