cbcvebase.

Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 5 of 12
CVE-2011-0246P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-08-04
CVE-2011-0246 [CRITICAL] CWE-119 CVE-2011-0246: Heap-based buffer overflow in Apple QuickTime before 7.7 on Windows allows remote attackers to execu Heap-based buffer overflow in Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.
nvd
CVE-2011-0245P3CRITICALCVSS 9.3≤ 7.6.9v7.0.0+30 more2011-08-04
CVE-2011-0245 [CRITICAL] CWE-119 CVE-2011-0245: Buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or c Buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted pict file.
nvd
CVE-2012-0666P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0666 [CRITICAL] CWE-119 CVE-2012-0666: Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote a Stack-based buffer overflow in the plugin in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTMovie object.
nvd
CVE-2011-0256P3CRITICALCVSS 9.3≤ 7.6.9v7.0.0+30 more2011-08-15
CVE-2011-0256 [CRITICAL] CWE-189 CVE-2011-0256: Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or Integer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted track run atoms in a QuickTime movie file.
nvd
CVE-2014-1243P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1243 [CRITICAL] CWE-119 CVE-2014-1243: Apple QuickTime before 7.7.5 does not initialize an unspecified pointer, which allows remote attacke Apple QuickTime before 7.7.5 does not initialize an unspecified pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted track list in a movie file.
nvd
CVE-2009-0957P3CRITICALCVSS 9.3v3.0v4.1.2+46 more2009-06-02
CVE-2009-0957 [CRITICAL] CWE-119 CVE-2009-0957: Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitr Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.
nvd
CVE-2009-0954P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0954 [CRITICAL] CWE-119 CVE-2009-0954: Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to exe Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region (CRGN) atom types.
nvd
CVE-2009-0953P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0953 [CRITICAL] CWE-119 CVE-2009-0953: Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitr Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
nvd
CVE-2011-0250P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-08-04
CVE-2011-0250 [CRITICAL] CWE-119 CVE-2011-0250: Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSS atoms in a QuickTime movie file.
nvd
CVE-2011-0251P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-08-04
CVE-2011-0251 [CRITICAL] CWE-119 CVE-2011-0251: Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSZ atoms in a QuickTime movie file.
nvd
CVE-2011-0249P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-08-04
CVE-2011-0249 [CRITICAL] CWE-119 CVE-2011-0249: Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STSC atoms in a QuickTime movie file.
nvd
CVE-2011-0252P3CRITICALCVSS 9.3≤ 7.6.9v7.0.0+30 more2011-08-04
CVE-2011-0252 [CRITICAL] CWE-119 CVE-2011-0252: Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrar Heap-based buffer overflow in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted STTS atoms in a QuickTime movie file.
nvd
CVE-2009-0952P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0952 [CRITICAL] CWE-119 CVE-2009-0952: Buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or Buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted compressed PSD image.
nvd
CVE-2011-3248P3CRITICALCVSS 9.3≤ 7.7v3.0+53 more2011-10-28
CVE-2011-3248 [CRITICAL] CWE-189 CVE-2011-3248: Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrar Integer signedness error in Apple QuickTime before 7.7.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font table in a QuickTime movie file.
nvd
CVE-2010-0527P3CRITICALCVSS 9.3≤ 7.6.0v7.0.0+20 more2010-03-31
CVE-2010-0527 [CRITICAL] CWE-189 CVE-2010-0527: Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbit Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
nvd
CVE-2011-3247P3CRITICALCVSS 9.3≤ 7.7.0v3.0+53 more2011-10-28
CVE-2011-3247 [CRITICAL] CWE-189 CVE-2011-3247: Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbit Integer overflow in Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT file.
nvd
CVE-2014-1247P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1247 [CRITICAL] CWE-119 CVE-2014-1247: Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted dref atom in a movie file.
nvd
CVE-2007-0712P3CRITICALCVSS 9.3≤ 7.1.4v3.0+25 more2007-03-05
CVE-2007-0712 [CRITICAL] CWE-119 CVE-2007-0712: Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.
nvd
CVE-2008-1021P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1021 [MEDIUM] CWE-119 CVE-2008-1021: Heap-based buffer overflow in Animation codec content handling in Apple QuickTime before 7.4.5 on Wi Heap-based buffer overflow in Animation codec content handling in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted movie with run length encoding.
nvd
CVE-2007-2295P3CRITICALCVSS 9.3v7.1v7.1.1+4 more2007-04-26
CVE-2007-2295 [CRITICAL] CWE-119 CVE-2007-2295: Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other ver Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 allows remote attackers to execute arbitrary code via a crafted H.264 MOV file.
nvd