Page 24 of 271 results (0.006 seconds)

CVSS: 10.0EPSS: 94%CPEs: 25EXPL: 0

Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation. El desbordamiento de búfer en la región heap de la memoria en el archivo QuickTime.qts en QuickTime de Apple anterior a versión 7.6.6 sobre Windows, permite a los atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (bloqueo de aplicación) por medio de una imagen PICT con un BkPixPat Opcode (0x12) que contiene valores diseñados que se utilizan en un cálculo para la asignación de memoria This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the primary QuickTime.qts library when parsing the BkPixPat opcode (0x12) within a PICT file. The application will use 2 fields within the file in a multiply which is then passed as an argument to an allocation. As both operands in the multiply are user-controllable, specific values can cause an under allocation which will later result in a heap overflow. • http://lists.apple.com/archives/security-announce/2010//Mar/msg00002.html http://www.securityfocus.com/archive/1/510569/100/0/threaded http://www.zerodayinitiative.com/advisories/ZDI-10-067 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6780 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 1%CPEs: 131EXPL: 0

Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file. Desbordamiento de búfer en Apple QuickTime en versiones anteriores a la v7.6.4 permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (caída de la aplicación) a través de un fichero de video MPEG-4 modificado. • http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html http://lists.apple.com/archives/security-announce/2009/Sep/msg00002.html http://support.apple.com/kb/HT3859 http://support.apple.com/kb/HT3937 http://www.securityfocus.com/bid/36328 http://www.vupen.com/english/advisories/2009/3184 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5672 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 1%CPEs: 130EXPL: 0

Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file. Apple QuickTime anterior a v7.6.4, permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de un fichero de película H.264 manipulado. • http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html http://lists.apple.com/archives/security-announce/2009/Sep/msg00002.html http://support.apple.com/kb/HT3859 http://support.apple.com/kb/HT3937 http://www.securityfocus.com/bid/36328 http://www.vupen.com/english/advisories/2009/3184 https://exchange.xforce.ibmcloud.com/vulnerabilities/53127 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5467 •

CVSS: 9.3EPSS: 59%CPEs: 131EXPL: 0

Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file. Desbordamiento de búfer basado en memoria dinámica (heap) en Apple QuickTime anterior a v7.6.4, permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (Caída de aplicación) a través de un archivo FlashPix manipulado. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists during the parsing of malformed FlashPix (.fpx) files. While parsing the SectorShift and cSectFat fields from the header, the application will multiply 2 user-controlled 32-bit values and utilize this for an allocation. • http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html http://lists.apple.com/archives/security-announce/2009/Sep/msg00002.html http://support.apple.com/kb/HT3859 http://support.apple.com/kb/HT3937 http://www.securityfocus.com/bid/36328 http://www.vupen.com/english/advisories/2009/3184 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6258 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 59%CPEs: 131EXPL: 0

Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file. Desbordamiento de búfer basado en memoria dinámica en Apple QuickTime anterior a v7.6.4, permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (caída de la aplicación) a través de un fichero de película H.264 manipulado. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists during the parsing of samples from a malformed MOV file utilizing the H.264 codec. While parsing data to render the stream, the application will mistrust a length that is used to initialize a heap chunk that was allocated in a header. • http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html http://lists.apple.com/archives/security-announce/2009/Sep/msg00002.html http://support.apple.com/kb/HT3859 http://support.apple.com/kb/HT3937 http://www.securityfocus.com/bid/36328 http://www.vupen.com/english/advisories/2009/3184 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6405 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •