
CVE-2008-0033
https://notcve.org/view.php?id=CVE-2008-0033
16 Jan 2008 — Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption. Una vulnerabilidad no especificada en Apple QuickTime versiones anteriores a 7.4, permite a los atacantes remotos causar una denegación de servicio (finalización de aplicación) y ejecutar código arbitrario por medio de un archivo d... • http://docs.info.apple.com/article.html?artnum=307301 • CWE-399: Resource Management Errors •

CVE-2008-0036
https://notcve.org/view.php?id=CVE-2008-0036
16 Jan 2008 — Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding. Desbordamiento de búfer en Apple QuickTime anterior a 7.4 permite a atacantes remotos ejecutar código de su elección a través de una imagen comprimida manipulada PICT, el cual dispara el desbordamiento durante la decodificación. • http://docs.info.apple.com/article.html?artnum=307301 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2008-0031
https://notcve.org/view.php?id=CVE-2008-0031
16 Jan 2008 — Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption. Vulnerabilidad no especificada en Apple QuickTime anterior a 7.4 permite a atacantes remotos provocar denegación de servicio (fin de la aplicación) y ejecutar código de su elección a través de un archivo de video manipulado Sorenson 3, el cual dispara corrupción de memoria. • http://docs.info.apple.com/article.html?artnum=307301 • CWE-399: Resource Management Errors •

CVE-2008-0234 – QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
https://notcve.org/view.php?id=CVE-2008-0234
11 Jan 2008 — Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message. Un desbordamiento de búfer en Apple Quicktime Player versión 7.3.1.70 y otras versiones anteriores a 7.4.1, cuando el tunelado de RTSP está habilitado, permite a atacantes remotos ejecutar código arbitrario por medio de una respuesta Reason-Phras... • https://www.exploit-db.com/exploits/4885 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-4706
https://notcve.org/view.php?id=CVE-2007-4706
15 Dec 2007 — Heap-based buffer overflow in Apple QuickTime before 7.3.1 allows remote attackers to execute arbitrary code via a crafted QTL file. Desbordamiento de búfer basado en pila en Apple QuickTime anterior a 7.3.1 permite a atacantes remotos ejecutar código de su elección mediante un fichero QTL artesanal. • http://docs.info.apple.com/article.html?artnum=307176 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-4707
https://notcve.org/view.php?id=CVE-2007-4707
15 Dec 2007 — Multiple unspecified vulnerabilities in the Flash media handler in Apple QuickTime before 7.3.1 allow remote attackers to execute arbitrary code or have other unspecified impacts via a crafted QuickTime movie. Múltiples vulnerabilidades sin especificar en el manejador Flash de Apple QuickTime, en versiones anteriores a la 7.3.1, permite que atacantes remotos ejecuten código a su elección, o que se produzcan otros impactos no especificados a través de películas QuickTime manipuladas. • http://docs.info.apple.com/article.html?artnum=307176 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-6238
https://notcve.org/view.php?id=CVE-2007-6238
04 Dec 2007 — Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories with actionable information. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. However, the orga... • http://wabisabilabi.blogspot.com/2007/11/quicktime-zeroday-vulnerability-still.html •

CVE-2007-6166 – Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH)
https://notcve.org/view.php?id=CVE-2007-6166
29 Nov 2007 — Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header. Un desbordamiento de búfer en la región stack de la memoria en Apple QuickTime anterior a la versión 7.3.1, como es usado en QuickTime Player en Windows XP y Safari en Mac OS X, permite a servidores remotos de Real Time Streaming Protocol (RTSP) e... • https://www.exploit-db.com/exploits/4648 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-4674
https://notcve.org/view.php?id=CVE-2007-4674
27 Nov 2007 — An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow. Un error de "aritmética de enteros" en Apple QuickTime 7.2 permite a atacantes remotos ejecutar código de su elección mediante un archivo de película manipulado que contiene un átomo de película (atom movie) con un valor de tamaño grande, lo cual dispara un desbordamiento de búfer basado ... • http://docs.info.apple.com/article.html?artnum=306896 • CWE-189: Numeric Errors •

CVE-2007-3750
https://notcve.org/view.php?id=CVE-2007-3750
07 Nov 2007 — Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via crafted Sample Table Sample Descriptor (STSD) atoms in a movie file. Desbordamiento de búfer basado en montículo en Apple QuickTime anterior a 7.3 permite a atacantes remotos ejecutar código de su elección mediante átomos Sample Table Sample Descriptor (STSD) manipulados en un archivo de película. • http://docs.info.apple.com/article.html?artnum=306896 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •