VDB
CVE-2005-2756
CVE-2005-2756
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
EPSS 4.24% · 90.7th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
4.24%
90.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | quicktime | 6.5.2, 0, 6.5.2 |
| n/a | n/a | n/a |
Timeline
- Nov 5, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- 20478 vdb
- 1015152 vdb
- 17428 third-party-advisory
- 144 third-party-advisory
- http://pb.specialised.info/all/adv/quicktime-pict-adv.txt url
- 20051104 Advisory: Apple QuickTime PICT Remote Memory Overwrite mailing-list
- http://www.kb.cert.org/vuls/id/855118 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-2756 advisory
- http://docs.info.apple.com/article.html?artnum=302772 url
- http://www.securityfocus.com/bid/15309 url
- http://www.vupen.com/english/advisories/2005/2293 url