Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-mozilla-develUpgrade firefoxUpgrade seamonkeyUpgrade firefox-jaUpgrade linux-seamonkey-develUpgrade linux-mozillaUpgrade linux-firefoxUpgrade mozillaUpgrade linux-firefox-develUpgrade linux-seamonkey | Dec 10, 2025 | Sep 19, 2007 |
| Mfsa2007 28 | — | Upgrade to Mozilla Firefox version 2.0.0.7 | Jun 14, 2012 | Sep 24, 2006 |
| Quicktime | — | Upgrade to Apple QuickTime version 7.1.5 | Oct 25, 2010 | Sep 24, 2006 |
| Suse | — | Upgrade seamonkey-mailUpgrade MozillaFirefoxUpgrade seamonkey-venkmanUpgrade mozilla-develUpgrade mozilla-huUpgrade mozilla-venkmanUpgrade mozilla-ircUpgrade mozilla-dom-inspectorUpgrade MozillaFirefox-translationsUpgrade mozilla-calendarUpgrade mozilla-mailUpgrade mozilla-csUpgrade seamonkey-spellcheckerUpgrade mozillaUpgrade mozilla-deatUpgrade seamonkey-ircUpgrade seamonkeyUpgrade suse-releaseUpgrade seamonkey-dom-inspector | Feb 17, 2015 | Sep 24, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub