VDB
CVE-2008-4116
CVE-2008-4116
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that leads to a heap-based buffer overflow.
EPSS 11.62% · 95.6th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
11.62%
95.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | quicktime | 7.5.5 |
| n/a | n/a | n/a |
| apple | itunes | 8.0 |
Timeline
- Sep 16, 2008 PoC Published
- Sep 17, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 4270 third-party-advisory
- oval:org.mitre.oval:def:5936 vdb
- oval:org.mitre.oval:def:7995 vdb
- 6471 exploit
- quicktime-itunes-checkstackcookie-bo(45311) vdb
- oval:org.mitre.oval:def:6113 vdb
- 31212 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-4116 advisory