VulnerabilityModified
CVE-2008-1013
Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
MEDIUM 6.8EPSS 4.13%
Does this matter?
Lower severity and a low EPSS score (4.13%). Track it; it rarely justifies an emergency change on its own.
Description
Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.13% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- apple/quicktime
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29650Patch, Vendor Advisory
- http://securitytracker.com/id?1019757
- http://support.apple.com/kb/HT1241
- http://www.securityfocus.com/bid/28583
- http://www.us-cert.gov/cas/techalerts/TA08-094A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2008/1078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41601
- http://secunia.com/advisories/29650Patch, Vendor Advisory
- http://securitytracker.com/id?1019757
- http://support.apple.com/kb/HT1241
- http://www.securityfocus.com/bid/28583
- http://www.us-cert.gov/cas/techalerts/TA08-094A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2008/1078
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41601
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.