CVE-2009-2799
published 2009-09-10CVE-2009-2799: Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash)…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.72%
92.2th percentile
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.6.2 | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5gvg-42jf-22j8: Heap-based buffer overflow in Apple QuickTime before 7
ghsa_unreviewed·2022-05-02
CVE-2009-2799 [HIGH] CWE-119 GHSA-5gvg-42jf-22j8: Heap-based buffer overflow in Apple QuickTime before 7
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.
Red Hat
kernel: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
vendor_redhat·2024-10-29·CVSS 5.5
CVE-2024-50085 [MEDIUM] CWE-416 kernel: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
kernel: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow
Syzkaller reported this splat:
BUG: KASAN: slab-use-after-free in mptcp_pm_nl_rm_addr_or_subflow+0xb44/0xcc0 net/mptcp/pm_netlink.c:881
Read of size 4 at addr ffff8880569ac858 by task syz.1.2799/14662
CPU: 0 UID: 0 PID: 14662 Comm: syz.1.2799 Not tainted 6.12.0-rc2-syzkaller-00307-g36c254515dc6 #0
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014
Call Trace:
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:377 [inline]
print_report+0xc3/0x620 mm/kasan/report.c:488
kas
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00002.htmlhttp://support.apple.com/kb/HT3859http://support.apple.com/kb/HT3937http://www.securityfocus.com/bid/36328http://www.vupen.com/english/advisories/2009/3184https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6405http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00002.htmlhttp://support.apple.com/kb/HT3859http://support.apple.com/kb/HT3937http://www.securityfocus.com/bid/36328http://www.vupen.com/english/advisories/2009/3184https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6405
2009-09-10
Published