Severity
9.3CRITICALNVD
OSV7.8
EPSS
52.8%
top 2.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 13
Latest updateJan 13

Description

Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDapple/mac_os_x9 versions+8
Linuxlinux/linux_kernel3.11.05.10.248+7

Patches

🔴Vulnerability Details

3
OSV
team: fix check for port enabled in team_queue_override_port_prio_changed()2026-01-13
OSV
net/hsr: fix NULL pointer dereference in prp_get_untagged_frame()2026-01-13
GHSA
GHSA-f2h2-4mgp-fcw2: Integer underflow in QuickDraw Manager in Apple Mac OS X 102022-05-02

💥Exploits & PoCs

1
Exploit-DB
Cisco VPN Client - Integer Overflow Denial of Service2009-11-21

📋Vendor Advisories

7
Red Hat
kernel: Linux kernel: Denial of Service via NULL pointer dereference in HSR2026-01-13
Red Hat
kernel: Linux kernel: Denial of Service via MPTCP race condition2026-01-13
Red Hat
kernel: iommu/vt-d: debugfs: Fix legacy mode page table dump logic2025-11-12
Red Hat
kernel: btrfs: avoid NULL pointer dereference if no valid csum tree2025-06-18
Red Hat
kernel: smb: client: fix oops due to unset link speed2025-02-27

🕵️Threat Intelligence

1
Wiz
CVE-2025-71088 Impact, Exploitability, and Mitigation Steps | Wiz