CVE-2008-3629Apple Quicktime vulnerability

CWE-3994 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
1.3%
top 19.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 11
Latest updateMay 2

Description

Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapple/quicktime7.5+19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-29rc-j772-rjx8: Apple QuickTime before 72022-05-02
CVEList
CVE-2008-3629: Apple QuickTime before 72008-09-10

💥Exploits & PoCs

1
Exploit-DB
Sybase MobiLink 10.0.1.3629 - Multiple Heap Buffer Overflow Vulnerabilities2008-02-20
CVE-2008-3629 — Apple Quicktime vulnerability | cvebase