cbcvebase.

Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 1 of 12
CVE-2007-6166P2CRITICALCVSS 9.3ExploitedPoC≤ 7.3v3.0+22 more2007-11-29
CVE-2007-6166 [CRITICAL] CWE-119 CVE-2007-6166: Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
nvd
CVE-2007-0015P2MEDIUMCVSS 6.8ExploitedPoCv7.1.32007-01-01
CVE-2007-0015 [MEDIUM] CVE-2007-0015: Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a lon Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
nvd
CVE-2004-0431P2MEDIUMCVSS 5.1Exploited≤ 6.52004-07-07
CVE-2004-0431 [MEDIUM] CVE-2004-0431: Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitra Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
nvd
CVE-2010-1818P2CRITICALCVSS 9.3PoCv6.0v6.0.0+45 more2010-08-31
CVE-2010-1818 [CRITICAL] CWE-824 CVE-2010-1818: The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, an The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.
nvd
CVE-2011-0257P2CRITICALCVSS 9.3PoC≤ 7.6.9v7.0.0+30 more2011-08-15
CVE-2011-0257 [CRITICAL] CWE-189 CVE-2011-0257: Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.
nvd
CVE-2012-3752P2CRITICALCVSS 9.3PoC≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3752 [CRITICAL] CWE-119 CVE-2012-3752: Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrar Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style element in a QuickTime TeXML file.
nvd
CVE-2012-3753P2CRITICALCVSS 9.3PoC≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3753 [CRITICAL] CWE-119 CVE-2012-3753: Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arb Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type.
nvd
CVE-2012-0663P2CRITICALCVSS 9.3PoC≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0663 [CRITICAL] CWE-119 CVE-2012-0663: Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attack Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.
nvd
CVE-2010-1799P2CRITICALCVSS 9.3PoCv3.0v4.1.2+50 more2010-08-16
CVE-2010-1799 [CRITICAL] CWE-119 CVE-2010-1799: Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Wi Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2013-1017P3CRITICALCVSS 9.3PoC≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1017 [CRITICAL] CWE-119 CVE-2013-1017: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file.
nvd
CVE-2012-3755P3CRITICALCVSS 9.3PoC≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3755 [CRITICAL] CWE-119 CVE-2012-3755: Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Targa image.
nvd
CVE-2008-0234P3CRITICALCVSS 9.3PoCv7.3.1.70v7.42008-01-11
CVE-2008-0234 [CRITICAL] CWE-119 CVE-2008-0234: Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunnel Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.
nvd
CVE-2009-0955P3CRITICALCVSS 9.3PoC≤ 7.6.1v3.0+47 more2009-06-02
CVE-2009-0955 [CRITICAL] CWE-94 CVE-2009-0955: Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue."
nvd
CVE-2008-4116P3CRITICALCVSS 9.3PoCv7.5.52008-09-18
CVE-2008-4116 [CRITICAL] CWE-119 CVE-2008-4116: Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that lea
nvd
CVE-2007-2394P3CRITICALCVSS 9.3PoCv7.0v7.0.1+9 more2007-07-15
CVE-2007-2394 [CRITICAL] CVE-2007-2394: Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted re Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.
nvd
CVE-2005-2340P3HIGHCVSS 7.5PoC≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-2340 [HIGH] CWE-119 CVE-2005-2340: Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitr Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.
nvd
CVE-2008-5406P3CRITICALCVSS 9.3PoCv7.5.52008-12-10
CVE-2008-5406 [CRITICAL] CWE-119 CVE-2008-5406: Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attack Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."
nvd
CVE-2008-0778P3HIGHCVSS 7.5PoC≤ 7.4.12008-02-14
CVE-2008-0778 [HIGH] CWE-119 CVE-2008-0778: Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4. Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix methods.
nvd
CVE-2007-0462P3CRITICALCVSS 10.0PoCv7.1.32007-01-26
CVE-2007-0462 [CRITICAL] CVE-2007-0462: The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
nvd
CVE-2006-4384P3MEDIUMCVSS 5.1PoC≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4384 [MEDIUM] CVE-2006-4384: Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.
nvd
1 / 12Next →
Apple Quicktime vulnerabilities | cvebase