CVE-2009-0003 – Apple QuickTime AVI Header nBlockAlign Heap Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2009-0003
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure. Un desbordamiento de búfer en la región heap de la memoria en Apple QuickTime anterior a la versión 7.6 permite a los atacantes remotos causar una denegación de servicio (terminación de aplicación) y ejecutar código arbitrario por medio de un archivo de película AVI con un valor nBlockAlign no válido en la estructura _WAVEFORMATEX. This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of AVI files. When the AVI header contains a malformed nBlockAlign value in the _WAVEFORMATEX structure, a heap overflow may occur which can be leveraged to execute arbitrary code under the context of the current user. • http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html http://osvdb.org/51526 http://secunia.com/advisories/33632 http://support.apple.com/kb/HT3403 http://www.securityfocus.com/bid/33387 http://www.us-cert.gov/cas/techalerts/TA09-022A.html http://www.vupen.com/english/advisories/2009/0212 http://www.zerodayinitiative.com/advisories/ZDI-09-006 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6218 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-0002 – Apple QuickTime VR Track Header Atom Heap Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2009-0002
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms. Desbordamiento de búfer basado en montículo en QuickTime de Apple antes de v7.6 permite a atacantes remotos provocar una denegación de servicio (cierre de la aplicación)y posiblemente ejecutar código de su elección mediante un archivo de vídeo QTVR con átomos THKD manipulados. This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Apple Quicktime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 'tkhd' atoms found inside QuickTimeVR files. Improper validation of the transform matrix data results in a heap chunk header overwrite leading to arbitrary code execution under the context of the currently logged in user. • http://archives.neohapsis.com/archives/bugtraq/2009-01/0210.html http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.html http://osvdb.org/51525 http://secunia.com/advisories/33632 http://support.apple.com/kb/HT3403 http://www.securityfocus.com/bid/33384 http://www.us-cert.gov/cas/techalerts/TA09-022A.html http://www.vupen.com/english/advisories/2009/0212 http://www.zerodayinitiative.com/advisories/ZDI-09-005 https://oval.cisecurity.org/repository/search/d • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2009-0123
https://notcve.org/view.php?id=CVE-2009-0123
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds. NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes. Vulnerabilidad inespecífica en Apple Safari en Mac OS X v10.5 y Windows permitiría a atacantes remotos leer ficheros de su elección en un cliente a través de vectores relacionados con la asociación de Safari con (1) suscripción (2) suscripciones y (3) búsqueda de suscripciones de tipo URL para suscripción de RSS. NOTA: Hasta el 14-01-2009 solo se ha revelado un preaviso vago. • http://brian.mastenbrook.net/display/27 http://isc.sans.org/diary.html?storyid=5689 http://secunia.com/advisories/33458 http://www.securityfocus.com/bid/33234 http://www.securitytracker.com/id?1021581 https://exchange.xforce.ibmcloud.com/vulnerabilities/47917 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2008-4219
https://notcve.org/view.php?id=CVE-2008-4219
The kernel in Apple Mac OS X before 10.5.6 allows local users to cause a denial of service (infinite loop and system halt) by running an application that is dynamically linked to libraries on an NFS server, related to occurrence of an exception in this application. El núcleo en Apple Mac OS X versiones anteriores a 10.5.6 permite a usuarios locales provocar una denegación de servicio (bucle infinito y parada del sistema) mediante la ejecución de una aplicación que está dinámicamente enlazada a librebrías en un servidor NFS, relacionado con la aparición de una excepción es esta aplicación. • http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html http://secunia.com/advisories/33179 http://support.apple.com/kb/HT3338 http://www.securityfocus.com/bid/32839 http://www.securityfocus.com/bid/32873 http://www.securitytracker.com/id?1021404 http://www.us-cert.gov/cas/techalerts/TA08-350A.html http://www.vupen.com/english/advisories/2008/3444 • CWE-399: Resource Management Errors •
CVE-2008-4236
https://notcve.org/view.php?id=CVE-2008-4236
Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file. Apple Type Services (ATS) de Apple Mac OS X v10.5 anterior a 10.5.6, permite a atacantes remotos provocar una denegación de servicio (bucle infinito) a través de una fuente manipulada insertada en un documento PDF. • http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.html http://secunia.com/advisories/33179 http://securitytracker.com/id?1021398 http://support.apple.com/kb/HT3338 http://www.securityfocus.com/bid/32839 http://www.securityfocus.com/bid/32875 http://www.us-cert.gov/cas/techalerts/TA08-350A.html http://www.vupen.com/english/advisories/2008/3444 • CWE-399: Resource Management Errors •