CVE-2007-0718
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.
Un desbordamiento de búfer en la región heap de la memoria en Apple QuickTime anterior a versión 7.1.5 permite a los atacantes remotos asistidos por el usuario causar una denegación de servicio (bloqueo) y posiblemente ejecutar código arbitrario por medio de un archivo QTIF con una descripción de muestra de video que contiene un ID de tabla Color de 0, que activa los corrupción de la memoria cuando QuickTime asume que existe una tabla de colores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-02-05 CVE Reserved
- 2007-03-05 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=486 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/313225 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/462012/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/22827 | Vdb Entry | |
http://www.securityfocus.com/bid/22839 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA07-065A.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32826 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://docs.info.apple.com/article.html?artnum=305149 | 2018-10-16 | |
http://secunia.com/advisories/24359 | 2018-10-16 | |
http://www.securitytracker.com/id?1017725 | 2018-10-16 |
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/Security-announce/2007/Mar/msg00000.html | 2018-10-16 | |
http://www.vupen.com/english/advisories/2007/0825 | 2018-10-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0 Search vendor "Apple" for product "Quicktime" and version "7.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.1 Search vendor "Apple" for product "Quicktime" and version "7.0.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.2 Search vendor "Apple" for product "Quicktime" and version "7.0.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.3 Search vendor "Apple" for product "Quicktime" and version "7.0.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.0.4 Search vendor "Apple" for product "Quicktime" and version "7.0.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1 Search vendor "Apple" for product "Quicktime" and version "7.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.1 Search vendor "Apple" for product "Quicktime" and version "7.1.1" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.2 Search vendor "Apple" for product "Quicktime" and version "7.1.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.3 Search vendor "Apple" for product "Quicktime" and version "7.1.3" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Quicktime Search vendor "Apple" for product "Quicktime" | 7.1.4 Search vendor "Apple" for product "Quicktime" and version "7.1.4" | - |
Affected
|