cbcvebase.
CVE-2012-3755
published 2012-11-09

CVE-2012-3755: Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

PriorityP353critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
10.18%
95.1th percentile
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
applequicktime<= 7.7.2
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime
applequicktime

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/22855.tga
processQuickTime PictureViewer.exe
  • Look for crafted TGA (Targa) image files being opened by QuickTime PictureViewer.exe; an invalid encoded width field in the TGA file triggers a heap-based buffer overflow.
  • Monitor QuickTime PictureViewer.exe for abnormal heap activity or crashes when processing .tga files, which may indicate exploitation of CVE-2012-3755.
  • ·Vulnerability affects Apple QuickTime versions up to and including 7.7.2; version 7.7.3 contains the fix. Ensure version checks target this range.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.