Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
0
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 12 of 12
CVE-2005-4092HIGHCVSS 7.5v7.0.32005-12-08
CVE-2005-4092 [HIGH] CWE-119 CVE-2005-4092: Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0
Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and
nvd
CVE-2005-2754MEDIUMCVSS 5.1≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2754 [MEDIUM] CWE-189 CVE-2005-2754: Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
nvd
CVE-2005-2756MEDIUMCVSS 5.1≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2756 [MEDIUM] CVE-2005-2756: Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrar
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
nvd
CVE-2005-2753MEDIUMCVSS 5.1≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2753 [MEDIUM] CWE-189 CVE-2005-2753: Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
nvd
CVE-2005-2755LOWCVSS 2.6≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2755 [LOW] CVE-2005-2755: Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (cra
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
nvd
CVE-2005-2743HIGHCVSS 7.5v6.5.22005-10-26
CVE-2005-2743 [HIGH] CVE-2005-2743: The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
nvd
CVE-2005-1579MEDIUMCVSS 5.0v7.02005-05-12
CVE-2005-1579 [MEDIUM] CVE-2005-1579: Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.
nvd
CVE-2004-0988MEDIUMCVSS 5.0v5.0.2v6.0+3 more2005-03-01
CVE-2004-0988 [MEDIUM] CVE-2004-0988: Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote att
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.
nvd
CVE-2004-0921HIGHCVSS 7.5v5.0.2v6.0+3 more2005-01-27
CVE-2004-0921 [HIGH] CVE-2004-0921: AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
nvd
CVE-2004-0922MEDIUMCVSS 5.0v5.0.2v6.0+3 more2005-01-27
CVE-2004-0922 [MEDIUM] CVE-2004-0922: AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest g
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
nvd
CVE-2004-0431MEDIUMCVSS 5.1≤ 6.52004-07-07
CVE-2004-0431 [MEDIUM] CVE-2004-0431: Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitra
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
nvd
CVE-2003-0168HIGHCVSS 7.5v5.0v6.02003-04-02
CVE-2003-0168 [HIGH] CVE-2003-0168: Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute
Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.
nvd
CVE-2002-0376HIGHCVSS 7.5v5.0.22002-09-24
CVE-2002-0376 [HIGH] CVE-2002-0376: Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrar
Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field.
nvd
CVE-2002-0252HIGHCVSS 7.5PoCv5.0.1v5.0.22002-05-29
CVE-2002-0252 [HIGH] CVE-2002-0252: Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitra
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.
nvd
CVE-2001-0198HIGHCVSS 7.6PoCv4.1.22001-05-03
CVE-2001-0198 [HIGH] CVE-2001-0198: Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbit
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.
nvd
← Previous12 / 12