CVE-2008-1583
- EPSS 11.97%
- Published 10.06.2008 18:32:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT image, a different vulnerability than CVE-2008-1581.
CVE-2008-1584
- EPSS 19.94%
- Published 10.06.2008 18:32:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in Indeo.qtx in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted Indeo video codec content in a movie file.
CVE-2008-1585
- EPSS 9.42%
- Published 10.06.2008 18:32:00
- Last modified 09.04.2025 00:30:58
Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary progr...
CVE-2008-2010
- EPSS 2.1%
- Published 30.04.2008 00:10:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute arbitrary code via a crafted QuickTime media file. NOTE: as of 20080429, the only disclosure is a vague pre-advisory with no actio...
CVE-2008-1013
- EPSS 2.9%
- Published 04.04.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
CVE-2008-1014
- EPSS 0.62%
- Published 04.04.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information.
CVE-2008-1015
- EPSS 9.45%
- Published 04.04.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the data reference atom handling in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.
CVE-2008-1016
- EPSS 1.42%
- Published 04.04.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Apple QuickTime before 7.4.5 does not properly handle movie media tracks, which allows remote attackers to execute arbitrary code via a crafted movie that triggers memory corruption.
CVE-2008-1017
- EPSS 26.21%
- Published 04.04.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.
CVE-2008-1018
- EPSS 40.58%
- Published 04.04.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via an MP4A movie with a malformed Channel Compositor (aka chan) atom.