CVE-2006-1463

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.

References

http://lists.apple.com/archives/security-announce/2006/May/msg00002.html

http://secunia.com/advisories/20069

http://securityreason.com/securityalert/888

http://securitytracker.com/id?1016067

http://www.securityfocus.com/archive/1/433828/100/0/threaded

http://www.securityfocus.com/bid/17953

http://www.us-cert.gov/cas/techalerts/TA06-132B.html

http://www.vupen.com/english/advisories/2006/1778

http://www.zerodayinitiative.com/advisories/ZDI-06-015.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/26396

Details

Source: MITRE

Published: 2006-05-12

Updated: 2018-10-18

Type: CWE-119

Risk Information

CVSS v2

Base Score: 5.1

Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 4.9

Severity: MEDIUM

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
21556QuickTime < 7.1 Multiple Vulnerabilities (Windows)NessusWindows
high
21554Quicktime < 7.1 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
high
3617Mac OS X Multiple Vulnerabilities (Security Update 2006-003)Nessus Network MonitorOperating System Detection
medium
3616Quicktime < 7.1 on Mac OS X Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
801197Quicktime < 7.1 on Mac OS X Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high