cbcvebase.

Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 7 of 12
CVE-2009-0188P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0188 [CRITICAL] CWE-399 CVE-2009-0188: Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file.
nvd
CVE-2012-3751P3CRITICALCVSS 9.3≤ 7.7.2v3.0+49 more2012-11-09
CVE-2012-3751 [CRITICAL] CWE-399 CVE-2012-3751: Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers t Use-after-free vulnerability in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with a crafted _qtactivex_ parameter in an OBJECT element.
nvd
CVE-2010-0536P3CRITICALCVSS 9.3≤ 7.6.0v7.0.0+20 more2010-03-31
CVE-2010-0536 [CRITICAL] CWE-119 CVE-2010-0536: Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.
nvd
CVE-2011-3251P3CRITICALCVSS 9.3≤ 7.7.0v3.0+53 more2011-10-28
CVE-2011-3251 [CRITICAL] CWE-119 CVE-2011-3251: Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a Apple QuickTime before 7.7.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted TKHD atoms in a QuickTime movie file.
nvd
CVE-2009-0005P3CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0005 [CRITICAL] CWE-399 CVE-2009-0005: Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.
nvd
CVE-2008-3628P3CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3628 [CRITICAL] CWE-399 CVE-2008-3628: Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, related to an "invalid pointer issue."
nvd
CVE-2005-3707P3HIGHCVSS 7.5≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-3707 [HIGH] CVE-2005-3707: Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code vi Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
nvd
CVE-2007-5045P3CRITICALCVSS 9.3≤ 7.1.52007-09-24
CVE-2007-5045 [CRITICAL] CVE-2007-5045: Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument. NOTE: this is a related issue to C
nvd
CVE-2012-0667P3CRITICALCVSS 9.3≤ 7.7.1v3.0+62 more2012-05-16
CVE-2012-0667 [CRITICAL] CWE-189 CVE-2012-0667: Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execu Integer signedness error in Apple QuickTime before 7.7.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted QTVR movie file.
nvd
CVE-2005-3710P3HIGHCVSS 7.5≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-3710 [HIGH] CWE-189 CVE-2005-3710: Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code v Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
nvd
CVE-2008-1020P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1020 [MEDIUM] CWE-119 CVE-2008-1020: Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 on Windows allows remote Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file with Kodak encoding, related to error checking and error messages.
nvd
CVE-2008-1018P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1018 [MEDIUM] CWE-119 CVE-2008-1018: Heap-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitr Heap-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via an MP4A movie with a malformed Channel Compositor (aka chan) atom.
nvd
CVE-2009-0956P3CRITICALCVSS 9.3≤ 7.6.1v3.0+48 more2009-06-02
CVE-2009-0956 [CRITICAL] CWE-399 CVE-2009-0956: Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie containing a user data atom of size zero.
nvd
CVE-2005-4092P3HIGHCVSS 7.5v7.0.32005-12-08
CVE-2005-4092 [HIGH] CWE-119 CVE-2005-4092: Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0 Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified Sample Description Table size value, and
nvd
CVE-2005-3713P3HIGHCVSS 7.5≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-3713 [HIGH] CWE-119 CVE-2005-3713: Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitr Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a GIF image file with a crafted Netscape Navigator Application Extension Block that modifies the heap in the Picture Modifier block.
nvd
CVE-2008-1013P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1013 [MEDIUM] CVE-2008-1013: Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, wh Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
nvd
CVE-2008-1016P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1016 [MEDIUM] CWE-94 CVE-2008-1016: Apple QuickTime before 7.4.5 does not properly handle movie media tracks, which allows remote attack Apple QuickTime before 7.4.5 does not properly handle movie media tracks, which allows remote attackers to execute arbitrary code via a crafted movie that triggers memory corruption.
nvd
CVE-2007-4673P3CRITICALCVSS 9.3v7.22007-10-04
CVE-2007-4673 [CRITICAL] CVE-2007-4673: Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote a Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.
nvd
CVE-2008-1019P3MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1019 [MEDIUM] CWE-119 CVE-2008-1019: Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 allows remote attackers Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted PICT image file, related to an improperly terminated memory copy loop.
nvd
CVE-2008-0033P3CRITICALCVSS 9.3≤ 7.3.1.702008-01-16
CVE-2008-0033 [CRITICAL] CWE-399 CVE-2008-0033: Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption.
nvd
Apple Quicktime vulnerabilities | cvebase