Apple Quicktime vulnerabilities

235 known vulnerabilities affecting apple/quicktime.

Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
0
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2

Vulnerabilities

Page 7 of 12
CVE-2009-0005CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0005 [CRITICAL] CWE-399 CVE-2009-0005: Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.
nvd
CVE-2009-0004CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0004 [CRITICAL] CWE-119 CVE-2009-0004: Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service ( Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.
nvd
CVE-2009-0002CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0002 [CRITICAL] CWE-119 CVE-2009-0002: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.
nvd
CVE-2009-0003CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0003 [CRITICAL] CWE-119 CVE-2009-0003: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.
nvd
CVE-2009-0007CRITICALCVSS 9.3≤ 7.5.5v3.0+43 more2009-01-21
CVE-2009-0007 [CRITICAL] CWE-119 CVE-2009-0007: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.
nvd
CVE-2009-0001CRITICALCVSS 9.3≤ 7.5.5v3.0+30 more2009-01-21
CVE-2009-0001 [CRITICAL] CWE-119 CVE-2009-0001: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.
nvd
CVE-2008-5406CRITICALCVSS 9.3PoCv7.5.52008-12-10
CVE-2008-5406 [CRITICAL] CWE-119 CVE-2008-5406: Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attack Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."
nvd
CVE-2008-4116CRITICALCVSS 9.3PoCv7.5.52008-09-18
CVE-2008-4116 [CRITICAL] CWE-119 CVE-2008-4116: Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or (3) .mov file, possibly related to the Check_stack_cookie function and an off-by-one error that lea
nvd
CVE-2008-3615CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3615 [CRITICAL] CWE-399 CVE-2008-3615: ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTi ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, accesses uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2008-3635CRITICALCVSS 9.3≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3635 [CRITICAL] CWE-119 CVE-2008-3635: Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
nvd
CVE-2008-3628CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3628 [CRITICAL] CWE-399 CVE-2008-3628: Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, related to an "invalid pointer issue."
nvd
CVE-2008-3627CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3627 [CRITICAL] CWE-399 CVE-2008-3627: Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within Quick Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within QuickTimeH264.qtx, (2) MDAT atoms in mov video files within QuickTimeH264.scalar, and (3) AVC1 atoms in an unknown media type within an unspecified component, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corrup
nvd
CVE-2008-3625CRITICALCVSS 9.3fixed in 7.5.52008-09-11
CVE-2008-3625 [CRITICAL] CWE-119 CVE-2008-3625: Stack-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbit Stack-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted (1) maxTilt, (2) minFieldOfView, and (3) maxFieldOfView elements in panorama track PDAT atoms.
nvd
CVE-2008-3614MEDIUMCVSS 6.8≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3614 [MEDIUM] CWE-189 CVE-2008-3614: Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbit Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.
nvd
CVE-2008-3624MEDIUMCVSS 6.8≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3624 [MEDIUM] CWE-119 CVE-2008-3624: Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitr Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms.
nvd
CVE-2008-3629MEDIUMCVSS 4.3≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3629 [MEDIUM] CWE-399 CVE-2008-3629: Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.
nvd
CVE-2008-3626MEDIUMCVSS 6.8≤ 7.4.5v3.0+26 more2008-09-11
CVE-2008-3626 [MEDIUM] CWE-119 CVE-2008-3626: The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly hand The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.
nvd
CVE-2008-1739MEDIUMCVSS 6.8≤ 7.4.4v3.0+26 more2008-09-03
CVE-2008-1739 [MEDIUM] CWE-399 CVE-2008-1739: Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possib Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted ftyp atoms in a movie file, which triggers memory corruption.
nvd
CVE-2008-1582MEDIUMCVSS 6.8v7.4.52008-06-10
CVE-2008-1582 [MEDIUM] CWE-399 CVE-2008-1582: Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AAC-encoded file that triggers memory corruption.
nvd
CVE-2008-1583MEDIUMCVSS 6.8≤ 7.4.52008-06-10
CVE-2008-1583 [MEDIUM] CVE-2008-1583: Heap-based buffer overflow in Apple QuickTime before 7.5 allows remote attackers to cause a denial o Heap-based buffer overflow in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT image, a different vulnerability than CVE-2008-1581.
nvd