Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 12 of 12
CVE-2011-0186P4MEDIUMCVSS 4.3fixed in 7.7.02011-03-23
CVE-2011-0186 [MEDIUM] CWE-787 CVE-2011-0186: QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause
QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.
nvd
CVE-2007-2389P4HIGHCVSS 7.1v7.1.62007-05-29
CVE-2007-2389 [HIGH] CVE-2007-2389: Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory b
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.
nvd
CVE-2004-0921P4HIGHCVSS 7.5v5.0.2v6.0+3 more2005-01-27
CVE-2004-0921 [HIGH] CVE-2004-0921: AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
nvd
CVE-2005-2756P4MEDIUMCVSS 5.1≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2756 [MEDIUM] CVE-2005-2756: Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrar
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
nvd
CVE-2005-2754P4MEDIUMCVSS 5.1≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2754 [MEDIUM] CWE-189 CVE-2005-2754: Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
nvd
CVE-2005-2753P4MEDIUMCVSS 5.1≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2753 [MEDIUM] CWE-189 CVE-2005-2753: Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
nvd
CVE-2007-2402P4MEDIUMCVSS 4.3v7.0v7.0.1+9 more2007-07-15
CVE-2007-2402 [MEDIUM] CWE-200 CVE-2007-2402: QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which
QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.
nvd
CVE-2011-0187P4MEDIUMCVSS 4.3fixed in 7.7.02011-03-23
CVE-2011-0187 [MEDIUM] CVE-2011-0187: The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same
The plug-in in QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via vectors involving a cross-site redirect.
nvd
CVE-2008-1014P4MEDIUMCVSS 4.3≤ 7.4.42008-04-04
CVE-2008-1014 [MEDIUM] CWE-20 CVE-2008-1014: Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote a
Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information.
nvd
CVE-2004-0922P4MEDIUMCVSS 5.0v5.0.2v6.0+3 more2005-01-27
CVE-2004-0922 [MEDIUM] CVE-2004-0922: AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest g
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
nvd
CVE-2005-1579P4MEDIUMCVSS 5.0v7.02005-05-12
CVE-2005-1579 [MEDIUM] CVE-2005-1579: Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.
nvd
CVE-2004-0988P4MEDIUMCVSS 5.0v5.0.2v6.0+3 more2005-03-01
CVE-2004-0988 [MEDIUM] CVE-2004-0988: Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote att
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.
nvd
CVE-2008-3629P4MEDIUMCVSS 4.3≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3629 [MEDIUM] CWE-399 CVE-2008-3629: Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash
Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.
nvd
CVE-2005-2755P4LOWCVSS 2.6≤ 7.0.2v6.5.2+2 more2005-11-05
CVE-2005-2755 [LOW] CVE-2005-2755: Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (cra
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
nvd
CVE-2010-0530P4LOWCVSS 2.1≤ 7.6.8v3.0+51 more2010-12-09
CVE-2010-0530 [LOW] CWE-264 CVE-2010-0530: Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in th
Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.
nvd
← Previous12 / 12