Unrated severityNVD Advisory· Published Dec 10, 2008· Updated Apr 23, 2026
CVE-2008-5406
CVE-2008-5406
Description
Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."
Affected products
2- cpe:2.3:a:apple:itunes:8.0.2.20:*:*:*:*:*:*:*
- cpe:2.3:a:apple:quicktime:7.5.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.