Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 10 of 12
CVE-2008-0032P4MEDIUMCVSS 5.8≤ 7.32008-01-16
CVE-2008-0032 [MEDIUM] CWE-399 CVE-2008-0032: Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file contai
Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.
nvd
CVE-2008-1584P4MEDIUMCVSS 6.8≤ 7.4.52008-06-10
CVE-2008-1584 [MEDIUM] CWE-119 CVE-2008-1584: Stack-based buffer overflow in Indeo.qtx in Apple QuickTime before 7.5 allows remote attackers to ca
Stack-based buffer overflow in Indeo.qtx in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted Indeo video codec content in a movie file.
nvd
CVE-2003-0168P4HIGHCVSS 7.5v5.0v6.02003-04-02
CVE-2003-0168 [HIGH] CVE-2003-0168: Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute
Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.
nvd
CVE-2007-0718P4MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0718 [MEDIUM] CWE-119 CVE-2007-0718: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTIF file with a Video Sample Description containing a Color table ID of 0, which triggers memory corruption when QuickTime assumes that a color table exists.
nvd
CVE-2011-0213P4MEDIUMCVSS 6.8fixed in 7.7.02011-06-24
CVE-2011-0213 [MEDIUM] CWE-120 CVE-2011-0213: Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbi
Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file.
nvd
CVE-2006-4389P4MEDIUMCVSS 5.1v5.0.2v6.0+12 more2006-09-12
CVE-2006-4389 [MEDIUM] CVE-2006-4389: Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a c
Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object.
nvd
CVE-2011-0211P4MEDIUMCVSS 6.8fixed in 7.7.02011-06-24
CVE-2011-0211 [MEDIUM] CWE-190 CVE-2011-0211: Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2011-0209P4MEDIUMCVSS 6.8fixed in 7.7.02011-06-24
CVE-2011-0209 [MEDIUM] CWE-190 CVE-2011-0209: Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arb
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.
nvd
CVE-2006-1453P4MEDIUMCVSS 5.1≤ 7.0.4v3.0+21 more2006-05-12
CVE-2006-1453 [MEDIUM] CWE-119 CVE-2006-1453: Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitra
Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.
nvd
CVE-2006-1460P4MEDIUMCVSS 5.1≤ 7.0.4v7.0+3 more2006-05-12
CVE-2006-1460 [MEDIUM] CWE-119 CVE-2006-1460: Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.
nvd
CVE-2015-7117P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7117 [MEDIUM] CVE-2015-7117: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and CVE-2015-7092.
nvdapple
CVE-2015-7088P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7088 [MEDIUM] CVE-2015-7088: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2006-1458P4MEDIUMCVSS 5.1v7.0.3v7.0.42006-05-12
CVE-2006-1458 [MEDIUM] CWE-189 CVE-2006-1458: Integer overflow in Apple QuickTime Player before 7.1 allows remote attackers to execute arbitrary c
Integer overflow in Apple QuickTime Player before 7.1 allows remote attackers to execute arbitrary code via a crafted JPEG image.
nvd
CVE-2007-0713P4MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0713 [MEDIUM] CVE-2007-0713: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie file.
nvd
CVE-2007-0715P4MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0715 [MEDIUM] CVE-2007-0715: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.
nvd
CVE-2008-3624P4MEDIUMCVSS 6.8≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3624 [MEDIUM] CWE-119 CVE-2008-3624: Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms.
nvd
CVE-2015-7090P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7090 [MEDIUM] CVE-2015-7090: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2015-7087P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7087 [MEDIUM] CVE-2015-7087: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2015-7089P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7089 [MEDIUM] CVE-2015-7089: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2006-1461P4MEDIUMCVSS 5.1≤ 7.0.4v7.0+3 more2006-05-12
CVE-2006-1461 [MEDIUM] CWE-119 CVE-2006-1461: Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.
nvd