VDB
CVE-2008-0778
CVE-2008-0778
PUBLISHED
CVSS 7.5 HIGH
Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix methods.
EPSS 9.21% · 94.8th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
9.21%
94.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | quicktime | 0 |
Timeline
- CVE Published
- Jul 30, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Aug 25, 2023 EPSS Score
References
- apple-quicktime-qtplugin-bo(40475) vdb
- 3652 third-party-advisory
- 27769 vdb
- 5110 exploit
- 20080212 QuickTime <= 7.4.1 QTPlugin.ocx Multiple Remote Stack Overflow mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-0778 advisory