Oval Definition:oval:org.mitre.oval:tst:80277
Comment:QuickTimePlayer.exe version is less than 7.5.5 (7.55.90.70)
Type:file_testNamespace:windows
Check_Existence:at_least_one_existsCheck:all
State Operator:AND
References
Object:oval:org.mitre.oval:obj:6558
State:oval:org.mitre.oval:ste:19983
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:15841
V
Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, related to an "invalid pointer issue"
2013-07-29
oval:org.mitre.oval:def:15851
V
Integer overflow in Apple QuickTime before 7.5.5 on Windows via a crafted PICT image, which triggers heap corruption
2013-07-29
oval:org.mitre.oval:def:15935
V
Stack-based buffer overflow in Apple QuickTime before 7.5.5 via a QuickTime Virtual Reality (QTVR) movie file with crafted (1) maxTilt, (2) minFieldOfView, and (3) maxFieldOfView elements in panorama track PDAT atoms
2013-07-29
oval:org.mitre.oval:def:16019
V
Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read
2013-07-29
oval:org.mitre.oval:def:16124
V
Heap-based buffer overflow in Apple QuickTime before 7.5.5 via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms
2013-07-29
oval:org.mitre.oval:def:16152
V
The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file
2013-07-29
oval:org.mitre.oval:def:16164
V
Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within QuickTimeH264.qtx, (2) MDAT atoms in mov video files within QuickTimeH264.scalar, and (3) AVC1 atoms in an unknown media type within an unspecified component, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a crafted, H.264 encoded movie file
2013-07-29
BACK