Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 6 of 12
CVE-2010-0528P3CRITICALCVSS 9.3≤ 7.6.0v7.0.0+22 more2010-03-31
CVE-2010-0528 [CRITICAL] CWE-119 CVE-2010-0528: Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.
nvd
CVE-2009-0185P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0185 [CRITICAL] CWE-119 CVE-2009-0185: Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted MS ADPCM encoded audio data in an AVI movie file.
nvd
CVE-2009-2203P3CRITICALCVSS 9.3≤ 7.6.2v3.0+49 more2009-09-10
CVE-2009-2203 [CRITICAL] CWE-119 CVE-2009-2203: Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or
Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file.
nvd
CVE-2009-0004P3CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0004 [CRITICAL] CWE-119 CVE-2009-0004: Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (
Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.
nvd
CVE-2015-5779P3HIGHCVSS 7.5v7.02015-08-17
CVE-2015-5779 [HIGH] CVE-2015-5779: QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3765, CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, and CVE-2015-5753.
nvdapple
CVE-2007-0754P3CRITICALCVSS 9.3≤ 7.1.22007-05-14
CVE-2007-0754 [CRITICAL] CVE-2007-0754: Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted Sample Table Sample Descriptor (STSD) atom size in a QuickTime movie.
nvd
CVE-2010-3802P3CRITICALCVSS 9.3≤ 7.6.8v3.0+50 more2010-12-09
CVE-2010-3802 [CRITICAL] CWE-189 CVE-2010-3802: Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrar
Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted panorama atom in a QuickTime Virtual Reality (QTVR) movie file.
nvd
CVE-2011-0258P3CRITICALCVSS 9.3≤ 7.6.9v3.0+52 more2011-09-06
CVE-2011-0258 [CRITICAL] CWE-119 CVE-2011-0258: Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a d
Apple QuickTime before 7.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image description associated with an mp4v tag in a movie file.
nvd
CVE-2012-3754P3CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3754 [CRITICAL] CWE-399 CVE-2012-3754: Use-after-free vulnerability in the Clear method in the ActiveX control in Apple QuickTime before 7.
Use-after-free vulnerability in the Clear method in the ActiveX control in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
nvd
CVE-2012-0665P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0665 [CRITICAL] CWE-119 CVE-2012-0665: Heap-based buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.
nvd
CVE-2014-1250P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1250 [CRITICAL] CWE-119 CVE-2014-1250: Apple QuickTime before 7.7.5 does not properly perform a byte-swapping operation, which allows remot
Apple QuickTime before 7.7.5 does not properly perform a byte-swapping operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted ttfo element in a movie file.
nvd
CVE-2014-1245P3CRITICALCVSS 9.3≤ 7.7.4v7.0.0+43 more2014-02-27
CVE-2014-1245 [CRITICAL] CWE-189 CVE-2014-1245: Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrar
Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted stsz atom in a movie file.
nvd
CVE-2006-2238P3HIGHCVSS 7.5≤ 7.0.4v7.0+3 more2006-05-12
CVE-2006-2238 [HIGH] CVE-2006-2238: Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrar
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.
nvd
CVE-2007-0714P3CRITICALCVSS 9.3≤ 7.1.4v3.0+25 more2007-03-05
CVE-2007-0714 [CRITICAL] CWE-189 CVE-2007-0714: Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a de
Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.
nvd
CVE-2009-0951P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0951 [CRITICAL] CWE-119 CVE-2009-0951: Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC compression file.
nvd
CVE-2007-3750P3CRITICALCVSS 9.3≤ 7.22007-11-07
CVE-2007-3750 [CRITICAL] CWE-119 CVE-2007-3750: Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrar
Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via crafted Sample Table Sample Descriptor (STSD) atoms in a movie file.
nvd
CVE-2007-2392P3CRITICALCVSS 9.3v7.0v7.0.1+9 more2007-07-15
CVE-2007-2392 [CRITICAL] CVE-2007-2392: Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to ex
Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.
nvd
CVE-2009-2799P3CRITICALCVSS 9.3≤ 7.6.2v3.0+49 more2009-09-10
CVE-2009-2799 [CRITICAL] CWE-119 CVE-2009-2799: Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.
nvd
CVE-2009-2798P3CRITICALCVSS 9.3≤ 7.6.2v3.0+49 more2009-09-10
CVE-2009-2798 [CRITICAL] CWE-119 CVE-2009-2798: Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitr
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
nvd
CVE-2009-2202P3CRITICALCVSS 9.3≤ 7.6.1v3.0+49 more2009-09-10
CVE-2009-2202 [CRITICAL] CVE-2009-2202: Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file.
nvd