CVE-2004-0431
EXPLOITEDApple QuickTime < 6.5.1 - Remote Code Execution via Malicious .mov Sample-to-Chunk Table
Title source: llmExploitation Summary
CVE-2004-0431 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
References (5)
Core 5
Core References
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/mhonarc/security-announce/msg00048.html
Mailing List mailing-list
x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=108356485013237&w=2
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16026
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/782958
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108360110618389&w=2
Scores
EPSS
0.0324
EPSS Percentile
87.0%
Details
VulnCheck KEV
2010-05-01
Status
published
Products (1)
apple/quicktime
< 6.5
Published
Jul 07, 2004
Tracked Since
Feb 18, 2026