Page 28 of 271 results (0.005 seconds)

CVSS: 9.3EPSS: 62%CPEs: 45EXPL: 0

Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow. El error en la propiedad signedness de enteros en Apple QuickTime en versiones anteriores 7.6, permite a los atacantes remotos causar una denegación de servicio (terminación de aplicación) y posiblemente ejecutar código arbitrario por medio de un archivo de película codificado de Cinepak con un átomo MDAT diseñado que desencadena un desbordamiento del búfer en la región heap de la memoria. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The specific flaw exists in the handling of movie data encoded using the Cinepak Video Codec. When parsing the data in the MDAT atom, there exists a signedness error which leads to a heap overflow. • http://archives.neohapsis.com/archives/bugtraq/2009-01/0215.html http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html http://osvdb.org/51529 http://secunia.com/advisories/33632 http://support.apple.com/kb/HT3403 http://www.securityfocus.com/archive/1/500391/100/0/threaded http://www.securityfocus.com/bid/33388 http://www.us-cert.gov/cas/techalerts/TA09-022A.html http://www.vupen.com/english/advisories/2009/0212 http://www.zerodayinitiative.com/adviso • CWE-189: Numeric Errors •

CVSS: 9.3EPSS: 88%CPEs: 45EXPL: 0

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms. Un desbordamiento del búfer en la región heap de la memoria en Apple QuickTime en versiones anteriores a 7.6, permite a los atacantes remotos causar una denegación de servicio (terminación de aplicación) y posiblemente ejecutar código arbitrario por medio de un archivo de película QuickTime que contiene datos de ancho de imagen no válidos en átomos JPEG dentro de átomos STSD. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must open a malicious file. The specific flaw exists in the handling of JPEG atoms embedded in STSD atoms within the function JPEG_DComponentDispatch(). When the image width data in this atom is modified, a heap corruption occurs which can be further leveraged to execute arbitrary code under the context of the current user. • http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html http://osvdb.org/51530 http://secunia.com/advisories/33632 http://support.apple.com/kb/HT3403 http://www.securityfocus.com/bid/33390 http://www.us-cert.gov/cas/techalerts/TA09-022A.html http://www.vupen.com/english/advisories/2009/0212 http://www.zerodayinitiative.com/advisories/ZDI-09-008 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6132 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 4%CPEs: 2EXPL: 1

Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow." Desbordamiento de búfer basado en pila en Apple QuickTime Player 7.5.5 e iTunes 8.0.2.20, permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) y probablemente la ejecución de código de su elección a través de un archivo MOV con "una argumento largo". Relacionado con un "error de superación de límite (off-by-one)". • https://www.exploit-db.com/exploits/7296 http://securityreason.com/securityalert/4704 http://www.securityfocus.com/bid/32540 https://exchange.xforce.ibmcloud.com/vulnerabilities/46984 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.3EPSS: 8%CPEs: 2EXPL: 1

Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that leads to a heap-based buffer overflow. Un desbordamiento del búfer en QuickTime versión 7.5.5 y iTunes versión 8.0, de Apple, permite a los atacantes remotos causar una denegación de servicio (bloqueo del navegador) o posiblemente ejecutar código arbitrario por medio de un atributo type largo en una etiqueta de quicktime (1) en una página web o insertado en un archivo ( 2) .mp4 o (3) .mov, posiblemente relacionado con la función Check_stack_cookie y un error por un paso que conduce a un desbordamiento del búfer en la región heap de la memoria. • https://www.exploit-db.com/exploits/6471 http://securityreason.com/securityalert/4270 http://www.securityfocus.com/bid/31212 https://exchange.xforce.ibmcloud.com/vulnerabilities/45311 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5936 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6113 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7995 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 6.8EPSS: 1%CPEs: 31EXPL: 0

Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms. Desbordamiento de búfer basado en montículo en Apple Quicktime anterior a 7.7.5 permite a atacantes remotos ejecutar código de su elección o provocar una denegación de servicio (caída de aplicación)a través de una película QuickTime Virtual Reality (QTVR)con átomos panorama manipulados. • http://lists.apple.com/archives/security-announce//2008/Sep/msg00000.html http://secunia.com/advisories/31821 http://securitytracker.com/id?1020841 http://support.apple.com/kb/HT3027 http://www.securityfocus.com/bid/31086 http://www.vupen.com/english/advisories/2008/2527 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16124 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •