CVE-2008-1739

Apple QuickTime < 7.4.5 - Remote Code Execution via Crafted Ftyp Atoms

Title source: llm
STIX 2.1

Description

Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted ftyp atoms in a movie file, which triggers memory corruption.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT1241
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45144

Scores

EPSS 0.0186
EPSS Percentile 77.1%

Details

CWE
CWE-399
Status published
Products (29)
apple/quicktime
apple/quicktime 3.0
apple/quicktime 5.0
apple/quicktime 5.0.1
apple/quicktime 5.0.2
apple/quicktime 6.0
apple/quicktime 6.1
apple/quicktime 6.5
apple/quicktime 6.5.1
apple/quicktime 6.5.2
... and 19 more
Published Sep 03, 2008
Tracked Since Feb 18, 2026