Advisories
OtherPoC exploitCRITICAL2008-04-03
Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted PICT image file, related to an improperly terminated memory copy loop.
CVEs:CVE-2008-1019
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherPoC exploitCRITICAL2008-04-15
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
CVEs:CVE-2008-3639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cups |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.
CVEs:CVE-2008-1017
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file with Kodak encoding, related to error checking and error messages.
CVEs:CVE-2008-1020
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Heap-based buffer overflow in Animation codec content handling in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted movie with run length encoding.
CVEs:CVE-2008-1021
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Stack-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted VR movie with an obji atom of zero size.
CVEs:CVE-2008-1022
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Buffer overflow in the data reference atom handling in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.
CVEs:CVE-2008-1015
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Heap-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via an MP4A movie with a malformed Channel Compositor (aka chan) atom.
CVEs:CVE-2008-1018
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Heap-based buffer overflow in Clip opcode parsing in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file.
CVEs:CVE-2008-1023
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-15
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
CVEs:CVE-2008-3640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cups |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
CVEs:CVE-2008-1013
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
SafariEPSS <= 49%CRITICAL2008-04-17
Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.
CVEs:CVE-2008-1024
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-03
Apple QuickTime before 7.4.5 does not properly handle movie media tracks, which allows remote attackers to execute arbitrary code via a crafted movie that triggers memory corruption.
CVEs:CVE-2008-1016
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%CRITICAL2008-04-04
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
CVEs:CVE-2008-1374
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| cups |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2008-04-29
Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute arbitrary code via a crafted QuickTime media file. NOTE: as of 20080429, the only disclosure is a vague pre-advisory with no actiona...
CVEs:CVE-2008-2010
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
OtherEPSS <= 49%HIGH2008-04-03
Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information.
CVEs:CVE-2008-1014
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| quicktime |
affected |
apple |
— |
— |
SafariEPSS <= 49%HIGH2008-04-28
Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that triggers an out-of-bounds access, possibly due to a NULL pointer dereference.
CVEs:CVE-2008-2001
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%MEDIUM2008-04-28
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
CVEs:CVE-2008-1999
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |
SafariEPSS <= 49%HIGH2008-04-28
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
CVEs:CVE-2008-2000
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| safari |
affected |
apple |
— |
— |