Use-after-free vulnerability in QuickTime in Apple Mac OS X 10.7.x before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Loginwindow | — | Apply OS X security update 2012-002Upgrade macOS to the latest version | Aug 28, 2015 | May 10, 2012 |
| Apple Osx Quicktime | — | Upgrade macOS to the latest version | Jul 16, 2012 | May 10, 2012 |
| Quicktime | — | Upgrade to Apple QuickTime version 7.7.2 | Jun 11, 2012 | May 10, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub