cbcvebase.

Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 4 of 12
CVE-2012-0668P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0668 [CRITICAL] CWE-119 CVE-2012-0668: Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with RLE encoding.
nvd
CVE-2014-1244P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1244 [CRITICAL] CWE-119 CVE-2014-1244: Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2014-1248P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1248 [CRITICAL] CWE-119 CVE-2014-1248: Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ldat atom in a movie file.
nvd
CVE-2014-1246P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1246 [CRITICAL] CWE-119 CVE-2014-1246: Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ftab atom in a movie file.
nvd
CVE-2014-1251P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1251 [CRITICAL] CWE-119 CVE-2014-1251: Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted clef atom in a movie file.
nvd
CVE-2013-1021P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1021 [CRITICAL] CWE-119 CVE-2013-1021: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG data in a movie file.
nvd
CVE-2013-0987P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-0987 [CRITICAL] CWE-399 CVE-2013-0987: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QTIF file.
nvd
CVE-2013-1015P3CRITICALCVSS 9.3≤ 7.7.3v3.0+50 more2013-05-24
CVE-2013-1015 [CRITICAL] CWE-119 CVE-2013-1015: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TeXML file.
nvd
CVE-2008-1017P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1017 [MEDIUM] CWE-119 CVE-2008-1017: Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple Qui Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.
nvd
CVE-2008-1022P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1022 [MEDIUM] CWE-119 CVE-2008-1022: Stack-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbit Stack-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted VR movie with an obji atom of zero size.
nvd
CVE-2012-0664P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0664 [CRITICAL] CWE-119 CVE-2012-0664: Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to exe Heap-based buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text track in a movie file.
nvd
CVE-2007-6238P3CRITICALCVSS 10.0v7.22007-12-04
CVE-2007-6238 [CRITICAL] CVE-2007-6238: Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute ar Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories
nvd
CVE-2012-0669P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0669 [CRITICAL] CWE-119 CVE-2012-0669: Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitr Buffer overflow in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.
nvd
CVE-2012-3758P3CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3758 [CRITICAL] CWE-119 CVE-2012-3758: Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted transform attribute in a text3GTrack element in a QuickTime TeXML file.
nvd
CVE-2010-3801P3CRITICALCVSS 9.3≤ 7.6.8v3.0+50 more2010-12-09
CVE-2010-3801 [CRITICAL] CWE-119 CVE-2010-3801: Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.
nvd
CVE-2010-3800P3CRITICALCVSS 9.3≤ 7.6.8v3.0+50 more2010-12-09
CVE-2010-3800 [CRITICAL] CWE-119 CVE-2010-3800: Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.
nvd
CVE-2010-4009P3CRITICALCVSS 9.3≤ 7.6.8v3.0+50 more2010-12-09
CVE-2010-4009 [CRITICAL] CWE-189 CVE-2010-4009: Integer overflow in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code o Integer overflow in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2012-0671P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0671 [CRITICAL] CWE-94 CVE-2012-0671: Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .pict file.
nvd
CVE-2012-3757P3CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3757 [CRITICAL] CVE-2012-3757: Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.
nvd
CVE-2010-1819P3CRITICALCVSS 9.3≤ 7.6.7v7.6.0+4 more2013-12-27
CVE-2010-1819 [CRITICAL] CVE-2010-1819: Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows loc Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) CoreVideo.dll, (2) CoreGraphics.dll, or (3) CoreAudioToolbox.dll that is located in the same folder as a .pic image file.
nvd
Apple Quicktime vulnerabilities | cvebase