← Back

CVE-2008-3626

nvd nist
Published: Sep 11, 2008Modified: Apr 23, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

Affected (29)

Products: Apple: Quicktime
1 product
Quicktime
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Up to 7.4.5
All versions
Version 3.0
Version 4.1.2
Version 5.0.1
Version 5.0.2
Version 5.0
Version 6.0
Version 6.5.1
Version 6.5.2
Version 6.5
Version 7.0.1
Version 7.0.2
Version 7.0.3
Version 7.0.4
Version 7.0
Version 7.1.1
Version 7.1.2
Version 7.1.3
Version 7.1.4
Version 7.1.5
Version 7.1.6
Version 7.1
Version 7.2
Version 7.3.1.70
Version 7.3.1
Version 7.3
Version 7.4.4
Version 7.4

References (28)

Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.