Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1585

Опубликовано: 10 июн. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apple:quicktime:*:*:*:*:*:*:*:*
Версия до 7.4.5 (включая)

EPSS

Процентиль: 93%
0.09415
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.

EPSS

Процентиль: 93%
0.09415
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-20