CVE-2007-6166

EXPLOITED

Apple QuickTime <7.3.1 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.

Exploits (10)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteosx
https://www.exploit-db.com/exploits/16873
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16424
exploitdb WORKING POC VERIFIED
by jacky · perlremotewindows
https://www.exploit-db.com/exploits/11027
exploitdb WORKING POC VERIFIED
by krafty · perlremoteosx
https://www.exploit-db.com/exploits/6013
exploitdb WORKING POC VERIFIED
by YAG KOHHA · textremotewindows
https://www.exploit-db.com/exploits/4664
exploitdb WORKING POC VERIFIED
by muts · pythonremotewindows
https://www.exploit-db.com/exploits/4657
exploitdb WORKING POC VERIFIED
by InTeL · c++remotewindows
https://www.exploit-db.com/exploits/4651
exploitdb WORKING POC VERIFIED
by h07 · pythondosmultiple
https://www.exploit-db.com/exploits/4648
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/apple_quicktime_rtsp_response.rb
metasploit WORKING POC NORMAL
rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/rtsp/quicktime_rtsp_content_type.rb

Scores

EPSS 0.8425
EPSS Percentile 99.3%

Details

VulnCheck KEV 2010-05-01
CWE
CWE-119
Status published
Products (26)
apple/quicktime
apple/quicktime 3.0
apple/quicktime 4.1.2
apple/quicktime 5.0
apple/quicktime 5.0.1
apple/quicktime 5.0.2
apple/quicktime 6.0
apple/quicktime 6.1
apple/quicktime 6.5
apple/quicktime 6.5.1
... and 16 more
Published Nov 29, 2007
Tracked Since Feb 18, 2026