Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and flags in an mvhd atom.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2014-004 | Aug 28, 2015 | Jul 26, 2014 |
| Apple Osx Qtmediafoundation | — | Upgrade macOS to the latest versionApply OS X security update 2014-004 | Sep 22, 2014 | Jul 26, 2014 |
| Quicktime | — | Upgrade to Apple QuickTime version 7.7.6 | Oct 24, 2014 | Jul 26, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub