Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object.
CVSS Details
- CVSS 3.1 Base Score: 5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade win32-codecs | Dec 10, 2025 | Sep 14, 2006 |
| Gentoo Linux | — | Upgrade media-libs/win32codecs. | Oct 30, 2017 | Sep 12, 2006 |
| Quicktime | — | Upgrade to Apple QuickTime version 7.1.3 | Sep 20, 2006 | Sep 12, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub