CVE Database
/

CVE-2006-4965

Back to search

CVE-2006-4965

Published: Sep 25, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.

VendorProductVersions

n/a

n/a

affected
n/a

References

1631
third-party-advisory
x_refsource_SREASON
VU#751808
third-party-advisory
x_refsource_CERT-VN
27414
third-party-advisory
x_refsource_SECUNIA
20070912 0DAY: QuickTime pwns Firefox
mailing-list
x_refsource_BUGTRAQ
1018687
vdb-entry
x_refsource_SECTRACK
20061207 New MySpace worm could be on its way
mailing-list
x_refsource_BUGTRAQ
APPLE-SA-2007-03-05
vendor-advisory
x_refsource_APPLE
ADV-2007-3155
vdb-entry
x_refsource_VUPEN
20138
vdb-entry
x_refsource_BID
22048
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now