CVE-2013-1020 – Apple QuickTime MJPEG Frame stsd Atom Heap Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-1020
Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file. Apple QuickTime antes de v7.7.4 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria) a través de datos JPEG manipulados en un archivo de película. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within processing a mjpeg movie with an improper jpeg frame size via the stsd atom. When processing the movie, the size of the destination buffer for jpeg contents is specified separately from the JPEG size. • http://lists.apple.com/archives/security-announce/2013/May/msg00001.html http://support.apple.com/kb/HT5770 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16365 • CWE-399: Resource Management Errors •
CVE-2013-1017 – Apple QuickTime dref Volume Name Parsing Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-1017
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file. Desbordamiento de búfer en Apple QuickTime antes de 7.7.4 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de átomos dref manipulados en un archivo de película. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of a MOV file. A dref atom can contain information specifying a past location of the MOV file. • https://www.exploit-db.com/exploits/27012 http://lists.apple.com/archives/security-announce/2013/May/msg00001.html http://support.apple.com/kb/HT5770 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16606 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-3752 – Apple QuickTime 7.7.2 - TeXML Style Element font-table Field Stack Buffer Overflow
https://notcve.org/view.php?id=CVE-2012-3752
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style element in a QuickTime TeXML file. Múltiples desbordamientos de búfer en Apple QuickTime antes de v7.7.3 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de un elemento style manipulado en un archivo QuickTime TeXML. • https://www.exploit-db.com/exploits/22905 http://lists.apple.com/archives/security-announce/2012/Nov/msg00002.html http://packetstormsecurity.com/files/118359/Apple-QuickTime-7.7.2-TeXML-Style-Element-font-table-Field-Stack-Buffer-Overflow.html http://secunia.com/advisories/51226 http://support.apple.com/kb/HT5581 http://www.securityfocus.com/bid/56557 https://exchange.xforce.ibmcloud.com/vulnerabilities/79899 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-3753 – Apple QuickTime 7.7.2 - MIME Type Buffer Overflow
https://notcve.org/view.php?id=CVE-2012-3753
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type. Desbordamiento de búfer en Apple QuickTime antes de v7.7.3 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de un tipo MIME manipulado. • https://www.exploit-db.com/exploits/22973 http://lists.apple.com/archives/security-announce/2012/Nov/msg00002.html http://packetstormsecurity.com/files/118421/Apple-QuickTime-7.7.2-MIME-Type-Buffer-Overflow.html http://secunia.com/advisories/51226 http://support.apple.com/kb/HT5581 https://exchange.xforce.ibmcloud.com/vulnerabilities/79900 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15947 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2011-1374
https://notcve.org/view.php?id=CVE-2011-1374
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted REGION record in a PICT file. Desbordamiento de búfer en Apple QuickTime antes de v7.7.3 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (caída de aplicación) a través de un documento HTML con un registro REGION manipulado en un archivo PICT. • http://lists.apple.com/archives/security-announce/2012/Nov/msg00002.html http://secunia.com/advisories/51226 http://support.apple.com/kb/HT5581 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15782 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •