cbcvebase.

Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 3 of 12
CVE-2007-4707P3CRITICALCVSS 9.3≤ 7.32007-12-15
CVE-2007-4707 [CRITICAL] CWE-119 CVE-2007-4707: Multiple unspecified vulnerabilities in the Flash media handler in Apple QuickTime before 7.3.1 allo Multiple unspecified vulnerabilities in the Flash media handler in Apple QuickTime before 7.3.1 allow remote attackers to execute arbitrary code or have other unspecified impacts via a crafted QuickTime movie.
nvd
CVE-2009-0003P3CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0003 [CRITICAL] CWE-119 CVE-2009-0003: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.
nvd
CVE-2013-1020P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1020 [CRITICAL] CWE-399 CVE-2013-1020: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file.
nvd
CVE-2011-0248P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-08-04
CVE-2011-0248 [CRITICAL] CWE-119 CVE-2011-0248: Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Window Stack-based buffer overflow in the QuickTime ActiveX control in Apple QuickTime before 7.7 on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTL file.
nvd
CVE-2009-0006P3CRITICALCVSS 9.3≤ 7.5.5v3.0+43 more2009-01-21
CVE-2009-0006 [CRITICAL] CWE-189 CVE-2009-0006: Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.
nvd
CVE-2009-0002P3CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0002 [CRITICAL] CWE-119 CVE-2009-0002: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.
nvd
CVE-2009-0007P3CRITICALCVSS 9.3≤ 7.5.5v3.0+43 more2009-01-21
CVE-2009-0007 [CRITICAL] CWE-119 CVE-2009-0007: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.
nvd
CVE-2012-3756P3CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3756 [CRITICAL] CWE-119 CVE-2012-3756: Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rnet box in an MP4 movie file.
nvd
CVE-2010-1508P3CRITICALCVSS 9.3≤ 7.6.8v3.0+51 more2010-12-09
CVE-2010-1508 [CRITICAL] CWE-119 CVE-2010-1508: Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to exe Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.
nvd
CVE-2007-2296P3CRITICALCVSS 9.3v7.1v7.1.1+4 more2007-04-26
CVE-2007-2296 [CRITICAL] CWE-189 CVE-2007-2296: Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.
nvd
CVE-2011-3249P3CRITICALCVSS 9.3≤ 7.7v3.0+53 more2011-10-28
CVE-2011-3249 [CRITICAL] CWE-119 CVE-2011-3249: Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with FLC encoding.
nvd
CVE-2011-1374P3CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2011-1374 [CRITICAL] CWE-119 CVE-2011-1374: Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted REGION record in a PICT file.
nvd
CVE-2013-0986P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-0986 [CRITICAL] CWE-119 CVE-2013-0986: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted enof atoms in a movie file.
nvd
CVE-2013-1018P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1018 [CRITICAL] CWE-119 CVE-2013-1018: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2013-1022P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1022 [CRITICAL] CWE-119 CVE-2013-1022: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.
nvd
CVE-2013-0988P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-0988 [CRITICAL] CWE-119 CVE-2013-0988: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FPX file.
nvd
CVE-2013-0989P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-0989 [CRITICAL] CWE-119 CVE-2013-0989: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP3 file.
nvd
CVE-2012-0670P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0670 [CRITICAL] CWE-189 CVE-2012-0670: Integer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code o Integer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted sean atom in a movie file.
nvd
CVE-2013-1016P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1016 [CRITICAL] CWE-119 CVE-2013-1016: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.263 encoding.
nvd
CVE-2011-3250P3CRITICALCVSS 9.3≤ 7.7v3.0+53 more2011-10-28
CVE-2011-3250 [CRITICAL] CWE-189 CVE-2011-3250: Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code o Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
nvd
Apple Quicktime vulnerabilities | cvebase