Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
0
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 10 of 12
CVE-2007-2295CRITICALCVSS 9.3v7.1v7.1.1+4 more2007-04-26
CVE-2007-2295 [CRITICAL] CWE-119 CVE-2007-2295: Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other ver
Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.
nvd
CVE-2007-0711CRITICALCVSS 9.3≤ 7.1.4v3.0+25 more2007-03-05
CVE-2007-0711 [CRITICAL] CWE-189 CVE-2007-0711: Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allow
Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.
nvd
CVE-2007-0712CRITICALCVSS 9.3≤ 7.1.4v3.0+25 more2007-03-05
CVE-2007-0712 [CRITICAL] CWE-119 CVE-2007-0712: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.
nvd
CVE-2007-0714CRITICALCVSS 9.3≤ 7.1.4v3.0+25 more2007-03-05
CVE-2007-0714 [CRITICAL] CWE-189 CVE-2007-0714: Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a de
Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.
nvd
CVE-2007-0713MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0713 [MEDIUM] CVE-2007-0713: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.
nvd
CVE-2007-0715MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0715 [MEDIUM] CVE-2007-0715: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.
nvd
CVE-2007-0718MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0718 [MEDIUM] CWE-119 CVE-2007-0718: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.
nvd
CVE-2007-0717MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0717 [MEDIUM] CVE-2007-0717: Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a de
Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.
nvd
CVE-2007-0716MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0716 [MEDIUM] CVE-2007-0716: Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.
nvd
CVE-2007-0588HIGHCVSS 7.1v7.1.32007-01-30
CVE-2007-0588 [HIGH] CVE-2007-0588: The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other application
The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overla
nvd
CVE-2007-0462CRITICALCVSS 10.0PoCv7.1.32007-01-26
CVE-2007-0462 [CRITICAL] CVE-2007-0462: The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.
nvd
CVE-2007-0059MEDIUMCVSS 6.8PoC≤ 7.1.3v3.02007-01-05
CVE-2007-0059 [MEDIUM] CVE-2007-0059: Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attacke
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.
nvd
CVE-2007-0015MEDIUMCVSS 6.8PoCv7.1.32007-01-01
CVE-2007-0015 [MEDIUM] CVE-2007-0015: Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a lon
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
nvd
CVE-2006-4965MEDIUMCVSS 5.0PoCv7.1.32006-09-25
CVE-2006-4965 [MEDIUM] CWE-94 CVE-2006-4965: Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript cod
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instance
nvd
CVE-2006-4388MEDIUMCVSS 5.1≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4388 [MEDIUM] CVE-2006-4388: Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute ar
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file.
nvd
CVE-2006-4385MEDIUMCVSS 5.1v5.0v5.0.1+13 more2006-09-12
CVE-2006-4385 [MEDIUM] CVE-2006-4385: Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arb
Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image.
nvd
CVE-2006-4386MEDIUMCVSS 5.1≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4386 [MEDIUM] CVE-2006-4386: Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute ar
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381.
nvd
CVE-2006-4389MEDIUMCVSS 5.1v5.0.2v6.0+12 more2006-09-12
CVE-2006-4389 [MEDIUM] CVE-2006-4389: Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a c
Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object.
nvd
CVE-2006-4384MEDIUMCVSS 5.1PoC≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4384 [MEDIUM] CVE-2006-4384: Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.
nvd
CVE-2006-4382MEDIUMCVSS 5.1≤ 7.1.2v5.0+14 more2006-09-12
CVE-2006-4382 [MEDIUM] CVE-2006-4382: Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to ex
Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie.
nvd