HIGH
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image
Published Oct 28, 2004
10.0
HIGHCVSS 2.0
EPSS 4.89%
Description
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
Affected products
No data.
Configuration 1
OR
- 1.0.4
- 1.0.4_8
- 1.1.1
- 1.1.4
- 1.1.4_2
- 1.1.4_3
- 1.1.4_5
- 1.1.6
- 1.1.7
- 1.1.10
- 1.1.12
- 1.1.13
- 1.1.14
- 1.1.15
- 1.1.16
- 1.1.17
- 1.1.18
- 1.1.19
- 1.1.19_rc5
- 1.1.20
- 1.1.21
Configuration 2
OR
- 10.2
- 10.2.1
- 10.2.2
- 10.2.3
- 10.2.4
- 10.2.5
- 10.2.6
- 10.2.7
- 10.2.8
- 10.3
- 10.3.1
- 10.3.2
- 10.3.3
- 10.3.4
- 10.3.5
- 10.2
- 10.2.1
- 10.2.2
- 10.2.3
- 10.2.4
- 10.2.5
- 10.2.6
- 10.2.7
- 10.2.8
- 10.3
- 10.3.1
- 10.3.2
- 10.3.3
- 10.3.4
- 10.3.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html vendor-advisoryx_refsource_APPLE
- http://www.securityfocus.com/bid/11322 vdb-entryx_refsource_BIDPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0924 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.apple.com/archives/security-announce/2004/Oct/msg00000.html | vendor-advisoryx_refsource_APPLEPatchVendor Advisory | |
| http://lists.apple.com/archives/security-announce/2004/Oct/msg00001.html | vendor-advisoryx_refsource_APPLE | |
| http://www.securityfocus.com/bid/11322 | vdb-entryx_refsource_BIDPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0924 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 28, 2004
Updated Sep 16, 2024
Reserved Sep 29, 2004
Link CVE-2004-0926
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2004-0924 Assigner mitre
Published Oct 28, 2004
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2004-0924