9.3

CVE-2009-0955

Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleQuicktime Update- Editionmac Version <= 7.6.1
AppleQuicktime Update- Editionwindows Version <= 7.6.1
AppleQuicktime Version-
AppleQuicktime Version3.0
AppleQuicktime Version4.1.2
AppleQuicktime Version4.1.2 Update- Editionmac
AppleQuicktime Version4.1.2 Update- Editionwindows
AppleQuicktime Version5.0
AppleQuicktime Version5.0.1
AppleQuicktime Version5.0.1 Update- Editionmac
AppleQuicktime Version5.0.1 Update- Editionwindows
AppleQuicktime Version5.0.2
AppleQuicktime Version5.0.2 Update- Editionmac
AppleQuicktime Version5.0.2 Update- Editionwindows
AppleQuicktime Version6.0
AppleQuicktime Version6.0 Update- Editionwindows
AppleQuicktime Version6.0.0
AppleQuicktime Version6.0.0 Update- Editionmac
AppleQuicktime Version6.0.0 Update- Editionwindows
AppleQuicktime Version6.0.1
AppleQuicktime Version6.0.1 Update- Editionmac
AppleQuicktime Version6.0.1 Update- Editionwindows
AppleQuicktime Version6.0.2
AppleQuicktime Version6.0.2 Update- Editionmac
AppleQuicktime Version6.0.2 Update- Editionwindows
AppleQuicktime Version6.1
AppleQuicktime Version6.1.0
AppleQuicktime Version6.1.0 Update- Editionmac
AppleQuicktime Version6.1.0 Update- Editionwindows
AppleQuicktime Version6.1.1
AppleQuicktime Version6.1.1 Update- Editionmac
AppleQuicktime Version6.1.1 Update- Editionwindows
AppleQuicktime Version6.2.0
AppleQuicktime Version6.2.0 Update- Editionmac
AppleQuicktime Version6.2.0 Update- Editionwindows
AppleQuicktime Version6.3.0
AppleQuicktime Version6.3.0 Update- Editionmac
AppleQuicktime Version6.3.0 Update- Editionwindows
AppleQuicktime Version6.4.0
AppleQuicktime Version6.4.0 Update- Editionmac
AppleQuicktime Version6.4.0 Update- Editionwindows
AppleQuicktime Version6.5
AppleQuicktime Version6.5.0
AppleQuicktime Version6.5.0 Update- Editionmac
AppleQuicktime Version6.5.0 Update- Editionwindows
AppleQuicktime Version6.5.1
AppleQuicktime Version6.5.1 Update- Editionmac
AppleQuicktime Version6.5.1 Update- Editionwindows
AppleQuicktime Version6.5.2
AppleQuicktime Version6.5.2 Update- Editionmac
AppleQuicktime Version6.5.2 Update- Editionwindows
AppleQuicktime Version7.0
AppleQuicktime Version7.0 Editionwindows
AppleQuicktime Version7.0 Update- Editionwindows
AppleQuicktime Version7.0.0
AppleQuicktime Version7.0.0 Update- Editionmac
AppleQuicktime Version7.0.0 Update- Editionwindows
AppleQuicktime Version7.0.1
AppleQuicktime Version7.0.1 Editionwindows
AppleQuicktime Version7.0.1 Update- Editionmac
AppleQuicktime Version7.0.1 Update- Editionwindows
AppleQuicktime Version7.0.2
AppleQuicktime Version7.0.2 Editionwindows
AppleQuicktime Version7.0.2 Update- Editionmac
AppleQuicktime Version7.0.2 Update- Editionwindows
AppleQuicktime Version7.0.3
AppleQuicktime Version7.0.3 Update- Editionmac
AppleQuicktime Version7.0.3 Update- Editionwindows
AppleQuicktime Version7.0.4
AppleQuicktime Version7.0.4 Update- Editionmac
AppleQuicktime Version7.0.4 Update- Editionwindows
AppleQuicktime Version7.1
AppleQuicktime Version7.1.0
AppleQuicktime Version7.1.0 Update- Editionmac
AppleQuicktime Version7.1.0 Update- Editionwindows
AppleQuicktime Version7.1.1
AppleQuicktime Version7.1.1 Update- Editionmac
AppleQuicktime Version7.1.1 Update- Editionwindows
AppleQuicktime Version7.1.2
AppleQuicktime Version7.1.2 Update- Editionmac
AppleQuicktime Version7.1.2 Update- Editionwindows
AppleQuicktime Version7.1.3
AppleQuicktime Version7.1.3 Update- Editionmac
AppleQuicktime Version7.1.3 Update- Editionwindows
AppleQuicktime Version7.1.4
AppleQuicktime Version7.1.4 Update- Editionmac
AppleQuicktime Version7.1.4 Update- Editionwindows
AppleQuicktime Version7.1.5
AppleQuicktime Version7.1.5 Update- Editionmac
AppleQuicktime Version7.1.5 Update- Editionwindows
AppleQuicktime Version7.1.6
AppleQuicktime Version7.1.6 Update- Editionmac
AppleQuicktime Version7.1.6 Update- Editionwindows
AppleQuicktime Version7.2
AppleQuicktime Version7.2 Editionvista
AppleQuicktime Version7.2.0
AppleQuicktime Version7.2.0 Update- Editionmac
AppleQuicktime Version7.2.0 Update- Editionwindows
AppleQuicktime Version7.2.1
AppleQuicktime Version7.2.1 Update- Editionmac
AppleQuicktime Version7.2.1 Update- Editionwindows
AppleQuicktime Version7.3
AppleQuicktime Version7.3.0
AppleQuicktime Version7.3.0 Update- Editionmac
AppleQuicktime Version7.3.0 Update- Editionwindows
AppleQuicktime Version7.3.1
AppleQuicktime Version7.3.1 Update- Editionmac
AppleQuicktime Version7.3.1 Update- Editionwindows
AppleQuicktime Version7.3.1.70
AppleQuicktime Version7.4
AppleQuicktime Version7.4.0
AppleQuicktime Version7.4.0 Update- Editionmac
AppleQuicktime Version7.4.0 Update- Editionwindows
AppleQuicktime Version7.4.1
AppleQuicktime Version7.4.1 Update- Editionmac
AppleQuicktime Version7.4.1 Update- Editionwindows
AppleQuicktime Version7.4.4
AppleQuicktime Version7.4.5 Update- Editionmac
AppleQuicktime Version7.4.5 Update- Editionwindows
AppleQuicktime Version7.5.0 Update- Editionmac
AppleQuicktime Version7.5.0 Update- Editionwindows
AppleQuicktime Version7.5.5 Update- Editionmac
AppleQuicktime Version7.5.5 Update- Editionwindows
AppleQuicktime Version7.6.0 Update- Editionmac
AppleQuicktime Version7.6.0 Update- Editionwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.45% 0.958
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.