CVE-2015-3791
published 2015-08-17CVE-2015-3791: QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.64%
88.4th percentile
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-3791: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 6.8
CVE-2015-3791 [MEDIUM] CVE-2015-3791: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-3791
Component: CVE-ID
Apple
CVE-2015-3791: QuickTime 7.7.8
vendor_apple·CVSS 6.8
CVE-2015-3791 [MEDIUM] CVE-2015-3791: QuickTime 7.7.8
Apple Security Update: About the security content of QuickTime 7.7.8
Product: QuickTime
Version: 7.7.8
CVE: CVE-2015-3791
Component: CVE-ID
GHSA
GHSA-pfx6-g54r-3jr5: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3790 [MEDIUM] CWE-119 GHSA-pfx6-g54r-3jr5: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-qc47-m83m-4r6c: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3789 [MEDIUM] CWE-119 GHSA-qc47-m83m-4r6c: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-5m8c-rwv8-x2qw: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3765 [MEDIUM] CWE-119 GHSA-5m8c-rwv8-x2qw: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-qf6m-3cvh-6rpj: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3788 [MEDIUM] CWE-119 GHSA-qf6m-3cvh-6rpj: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-3gj5-w9pw-v55w: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-5779 [MEDIUM] CWE-119 GHSA-3gj5-w9pw-v55w: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, and CVE-2015-5753.
GHSA
GHSA-r2v7-8c94-h6vr: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3791 [MEDIUM] CWE-119 GHSA-r2v7-8c94-h6vr: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-h298-r3hv-47fj: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-5751 [MEDIUM] CWE-119 GHSA-h298-r3hv-47fj: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-hphh-mp7v-g43f: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3792 [MEDIUM] CWE-119 GHSA-hphh-mp7v-g43f: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-x45h-56wr-hcq3: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3779 [MEDIUM] CWE-119 GHSA-x45h-56wr-hcq3: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
GHSA
GHSA-8v59-2g65-956m: QuickTime 7 in Apple OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-5753 [MEDIUM] CWE-119 GHSA-8v59-2g65-956m: QuickTime 7 in Apple OS X before 10
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, and CVE-2015-5779.
No detection rules found.
No public exploits indexed.
Talos
Talos Identifies Multiple Memory Corruption Issues in Quicktime
blogs_talos·2015-08-13·CVSS 6.8
[MEDIUM] Talos Identifies Multiple Memory Corruption Issues in Quicktime
## Talos Identifies Multiple Memory Corruption Issues in Quicktime
Update 2015-08-21 : This post has been updated to reflect an additional advisory released on August 20.
Talos, in conjunction with Apple’s security advisories issued on August 13 and August 20, has released six advisories for vulnerabilities that Talos found in Apple Quicktime. In accordance with our Vendor Vulnerability Reporting and Disclosure policy, these vulnerabilities have been reported to Apple and CERT. This post serves as a summary for the advisories being released in coordination with Apple and CERT.
Ryan Pentney and Richard Johnson of Talos are credited with the discovery of these vulnerabilities.
## Advisory Summary Several memory corruption vulnerabilities exist in Apple Quicktime and can manifest themselv
Talos
Talos Identifies Multiple Memory Corruption Issues in Quicktime
blogs_talos·2015-08-13·CVSS 6.8
[MEDIUM] Talos Identifies Multiple Memory Corruption Issues in Quicktime
Update 2015-08-21: This post has been updated to reflect an additional advisory released on August 20.
Talos, in conjunction with Apple’s security advisories issued on August 13 and August 20, has released six advisories for vulnerabilities that Talos found in Apple Quicktime. In accordance with our Vendor Vulnerability Reporting and Disclosure policy, these vulnerabilities have been reported to Apple and CERT. This post serves as a summary for the advisories being released in coordination with Apple and CERT.
Ryan Pentney and Richard Johnson of Talos are credited with the discovery of these vulnerabilities.
### Advisory Summary Several memory corruption vulnerabilities exist in Apple Quicktime and can manifest themselves due to improper handling of objects in memory. An adversary who c
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00004.htmlhttp://www.securityfocus.com/bid/76340http://www.securitytracker.com/id/1033276https://support.apple.com/HT205046https://support.apple.com/kb/HT205031http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Aug/msg00004.htmlhttp://www.securityfocus.com/bid/76340http://www.securitytracker.com/id/1033276https://support.apple.com/HT205046https://support.apple.com/kb/HT205031
2015-08-17
Published