CVE-2004-0431

EXPLOITED

Apple QuickTime < 6.5.1 - Remote Code Execution via Malicious .mov Sample-to-Chunk Table

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2004-0431 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.

References (5)

Core 5
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/mhonarc/security-announce/msg00048.html
Mailing List mailing-list x_refsource_ntbugtraq
http://marc.info/?l=ntbugtraq&m=108356485013237&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16026
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/782958
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108360110618389&w=2

Scores

EPSS 0.0324
EPSS Percentile 87.0%

Details

VulnCheck KEV 2010-05-01
Status published
Products (1)
apple/quicktime < 6.5
Published Jul 07, 2004
Tracked Since Feb 18, 2026