cbcvebase.

Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 2 of 12
CVE-2002-0252P4HIGHCVSS 7.5PoCv5.0.1v5.0.22002-05-29
CVE-2002-0252 [HIGH] CVE-2002-0252: Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitra Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.
nvd
CVE-2001-0198P4HIGHCVSS 7.6PoCv4.1.22001-05-03
CVE-2001-0198 [HIGH] CVE-2001-0198: Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbit Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.
nvd
CVE-2007-0059P4MEDIUMCVSS 6.8PoC≤ 7.1.3v3.02007-01-05
CVE-2007-0059 [MEDIUM] CVE-2007-0059: Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attacke Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.
nvd
CVE-2007-2397P3CRITICALCVSS 9.3v7.0v7.0.1+9 more2007-07-15
CVE-2007-2397 [CRITICAL] CVE-2007-2397: QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows r QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.
nvd
CVE-2006-4965P4MEDIUMCVSS 5.0PoCv7.1.32006-09-25
CVE-2006-4965 [MEDIUM] CWE-94 CVE-2006-4965: Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript cod Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instance
nvd
CVE-2007-2396P3CRITICALCVSS 9.3v7.0v7.0.1+9 more2007-07-15
CVE-2007-2396 [CRITICAL] CVE-2007-2396: The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous in The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets.
nvd
CVE-2010-0529P3CRITICALCVSS 9.3≤ 7.6.0v7.0.0+20 more2010-03-31
CVE-2010-0529 [CRITICAL] CWE-119 CVE-2010-0529: Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.
nvd
CVE-2007-4672P3HIGHCVSS 7.6≤ 7.22007-11-07
CVE-2007-4672 [HIGH] CWE-119 CVE-2007-4672: Stack-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitra Stack-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid UncompressedQuickTimeData opcode length in a PICT image.
nvd
CVE-2011-0247P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-08-04
CVE-2011-0247 [CRITICAL] CWE-119 CVE-2011-0247: Multiple stack-based buffer overflows in Apple QuickTime before 7.7 on Windows allow remote attacker Multiple stack-based buffer overflows in Apple QuickTime before 7.7 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie.
nvd
CVE-2011-3428P3CRITICALCVSS 9.8≤ 7.7.62017-04-24
CVE-2011-3428 [CRITICAL] CWE-119 CVE-2011-3428: Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary c Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.
nvd
CVE-2007-2393P3CRITICALCVSS 9.3v7.0v7.0.1+9 more2007-07-15
CVE-2007-2393 [CRITICAL] CVE-2007-2393: The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass cer The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.
nvd
CVE-2012-0265P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0265 [CRITICAL] CWE-119 CVE-2012-0265: Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to ex Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pathname for a file.
nvd
CVE-2008-3627P3CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3627 [CRITICAL] CWE-399 CVE-2008-3627: Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within Quick Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within QuickTimeH264.qtx, (2) MDAT atoms in mov video files within QuickTimeH264.scalar, and (3) AVC1 atoms in an unknown media type within an unspecified component, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corrup
nvd
CVE-2007-2395P3CRITICALCVSS 9.3≤ 7.22007-11-07
CVE-2007-2395 [CRITICAL] CVE-2007-2395: Unspecified vulnerability in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary Unspecified vulnerability in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a crafted image description atom in a movie file, related to "memory corruption."
nvd
CVE-2009-0001P3CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0001 [CRITICAL] CWE-119 CVE-2009-0001: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.
nvd
CVE-2008-3625P3CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3625 [CRITICAL] CWE-119 CVE-2008-3625: Stack-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbit Stack-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted (1) maxTilt, (2) minFieldOfView, and (3) maxFieldOfView elements in panorama track PDAT atoms.
nvd
CVE-2008-3635P3CRITICALCVSS 9.3≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3635 [CRITICAL] CWE-119 CVE-2008-3635: Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2007-2388P3CRITICALCVSS 9.3v7.1.62007-05-29
CVE-2007-2388 [CRITICAL] CWE-264 CVE-2007-2388: Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassi Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
nvd
CVE-2013-1019P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1019 [CRITICAL] CWE-119 CVE-2013-1019: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
nvd
CVE-2014-1249P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1249 [CRITICAL] CWE-119 CVE-2014-1249: Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PSD image.
nvd
Apple Quicktime vulnerabilities | cvebase