Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
0
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 4 of 12
CVE-2012-3753CRITICALCVSS 9.3PoC≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3753 [CRITICAL] CWE-119 CVE-2012-3753: Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arb
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME type.
nvd
CVE-2012-3758CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3758 [CRITICAL] CWE-119 CVE-2012-3758: Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribute in a text3GTrack element in a QuickTime TeXML file.
nvd
CVE-2012-0669CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0669 [CRITICAL] CWE-119 CVE-2012-0669: Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitr
Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
nvd
CVE-2012-0671CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0671 [CRITICAL] CWE-94 CVE-2012-0671: Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .pict file.
nvd
CVE-2012-0667CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0667 [CRITICAL] CWE-189 CVE-2012-0667: Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execu
Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTVR movie file.
nvd
CVE-2012-0670CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0670 [CRITICAL] CWE-189 CVE-2012-0670: Integer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code o
Integer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted sean atom in a movie file.
nvd
CVE-2012-0666CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0666 [CRITICAL] CWE-119 CVE-2012-0666: Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote a
Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTMovie object.
nvd
CVE-2012-0663CRITICALCVSS 9.3PoC≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0663 [CRITICAL] CWE-119 CVE-2012-0663: Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attack
Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TeXML file.
nvd
CVE-2012-0664CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0664 [CRITICAL] CWE-119 CVE-2012-0664: Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to exe
Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text track in a movie file.
nvd
CVE-2012-0665CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0665 [CRITICAL] CWE-119 CVE-2012-0665: Heap-based buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2012-0668CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0668 [CRITICAL] CWE-119 CVE-2012-0668: Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or
Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding.
nvd
CVE-2012-0265CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0265 [CRITICAL] CWE-119 CVE-2012-0265: Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to ex
Stack-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pathname for a file.
nvd
CVE-2011-3247CRITICALCVSS 9.3≤ 7.7.0v3.0+53 more2011-10-28
CVE-2011-3247 [CRITICAL] CWE-189 CVE-2011-3247: Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbit
Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.
nvd
CVE-2011-3248CRITICALCVSS 9.3≤ 7.7v3.0+53 more2011-10-28
CVE-2011-3248 [CRITICAL] CWE-189 CVE-2011-3248: Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrar
Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.
nvd
CVE-2011-3250CRITICALCVSS 9.3≤ 7.7v3.0+53 more2011-10-28
CVE-2011-3250 [CRITICAL] CWE-189 CVE-2011-3250: Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code o
Integer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with JPEG2000 encoding.
nvd
CVE-2011-3249CRITICALCVSS 9.3≤ 7.7v3.0+53 more2011-10-28
CVE-2011-3249 [CRITICAL] CWE-119 CVE-2011-3249: Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or
Buffer overflow in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with FLC encoding.
nvd
CVE-2011-3251CRITICALCVSS 9.3≤ 7.7.0v3.0+53 more2011-10-28
CVE-2011-3251 [CRITICAL] CWE-119 CVE-2011-3251: Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a
Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.
nvd
CVE-2011-0258CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-09-06
CVE-2011-0258 [CRITICAL] CWE-119 CVE-2011-0258: Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a d
Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image description associated with an mp4v tag in a movie file.
nvd
CVE-2011-0256CRITICALCVSS 9.3≤ 7.6.9v7.0.0+30 more2011-08-15
CVE-2011-0256 [CRITICAL] CWE-189 CVE-2011-0256: Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or
Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted track run atoms in a QuickTime movie file.
nvd
CVE-2011-0257CRITICALCVSS 9.3PoC≤ 7.6.9v7.0.0+30 more2011-08-15
CVE-2011-0257 [CRITICAL] CWE-189 CVE-2011-0257: Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.
nvd