Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 11 of 12
CVE-2005-3709P4HIGHCVSS 7.5≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-3709 [HIGH] CWE-189 CVE-2005-3709: Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of servi
Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file.
nvd
CVE-2008-1582P4MEDIUMCVSS 6.8v7.4.52008-06-10
CVE-2008-1582 [MEDIUM] CWE-399 CVE-2008-1582: Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of
Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AAC-encoded file that triggers memory corruption.
nvd
CVE-2007-0716P4MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0716 [MEDIUM] CVE-2007-0716: Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to
Stack-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.
nvd
CVE-2007-4706P4MEDIUMCVSS 6.8≤ 7.32007-12-15
CVE-2007-4706 [MEDIUM] CWE-119 CVE-2007-4706: Heap-based buffer overflow in Apple QuickTime before 7.3.1 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.3.1 allows remote attackers to execute arbitrary code via a crafted QTL file.
nvd
CVE-2006-1464P4MEDIUMCVSS 5.1v7.0.3v7.0.42006-05-12
CVE-2006-1464 [MEDIUM] CVE-2006-1464: Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.
nvd
CVE-2006-4385P4MEDIUMCVSS 5.1v5.0v5.0.1+13 more2006-09-12
CVE-2006-4385 [MEDIUM] CVE-2006-4385: Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arb
Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image.
nvd
CVE-2008-1739P4MEDIUMCVSS 6.8≤ 7.4.4v3.0+26 more2008-09-03
CVE-2008-1739 [MEDIUM] CWE-399 CVE-2008-1739: Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possib
Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted ftyp atoms in a movie file, which triggers memory corruption.
nvd
CVE-2015-7091P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7091 [MEDIUM] CVE-2015-7091: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2015-7086P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7086 [MEDIUM] CVE-2015-7086: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2015-7085P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7085 [MEDIUM] CWE-119 CVE-2015-7085: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and CVE-2015-7117.
nvdapple
CVE-2006-1462P4MEDIUMCVSS 5.1≤ 7.0.4v7.0.0+3 more2006-05-12
CVE-2006-1462 [MEDIUM] CWE-189 CVE-2006-1462: Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary
Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.
nvd
CVE-2006-4386P4MEDIUMCVSS 5.1≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4386 [MEDIUM] CVE-2006-4386: Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute ar
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381.
nvd
CVE-2006-1459P4MEDIUMCVSS 5.1≤ 7.0.4v7.0.0+3 more2006-05-12
CVE-2006-1459 [MEDIUM] CWE-189 CVE-2006-1459: Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of
Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).
nvd
CVE-2006-4381P4MEDIUMCVSS 5.1≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4381 [MEDIUM] CVE-2006-4381: Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute ar
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie.
nvd
CVE-2002-0376P4HIGHCVSS 7.5v5.0.22002-09-24
CVE-2002-0376 [HIGH] CVE-2002-0376: Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrar
Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field.
nvd
CVE-2006-4388P4MEDIUMCVSS 5.1≤ 7.1.2v5.0+13 more2006-09-12
CVE-2006-4388 [MEDIUM] CVE-2006-4388: Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute ar
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file.
nvd
CVE-2006-1465P4MEDIUMCVSS 5.1v7.0.3v7.0.42006-05-12
CVE-2006-1465 [MEDIUM] CVE-2006-1465: Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.
nvd
CVE-2007-0588P4HIGHCVSS 7.1v7.1.32007-01-30
CVE-2007-0588 [HIGH] CVE-2007-0588: The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other application
The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overla
nvd
CVE-2008-0031P4MEDIUMCVSS 5.8≤ 7.32008-01-16
CVE-2008-0031 [MEDIUM] CWE-399 CVE-2008-0031: Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of
Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption.
nvd
CVE-2007-0717P4MEDIUMCVSS 5.8v7.0v7.0.1+8 more2007-03-05
CVE-2007-0717 [MEDIUM] CVE-2007-0717: Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a de
Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.
nvd