Apple Quicktime vulnerabilities
235 known vulnerabilities affecting apple/quicktime.
Total CVEs
235
CISA KEV
0
Public exploits
23
Exploited in wild
3
Severity breakdown
CRITICAL118HIGH20MEDIUM95LOW2
Vulnerabilities
Page 9 of 12
CVE-2015-3765P4MEDIUMCVSS 6.8v7.0.02015-08-16
CVE-2015-3765 [MEDIUM] CWE-119 CVE-2015-3765: QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause
QuickTime 7 in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-3779, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-5751, CVE-2015-5753, and CVE-2015-5779.
nvd
CVE-2015-3664P4MEDIUMCVSS 6.8≤ 7.7.62015-07-03
CVE-2015-3664 [MEDIUM] CWE-119 CVE-2015-3664: QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary cod
QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3665 and CVE-2015-3669.
nvdapple
CVE-2015-3669P4MEDIUMCVSS 6.8≤ 7.7.62015-07-03
CVE-2015-3669 [MEDIUM] CVE-2015-3669: QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary cod
QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3665.
nvdapple
CVE-2015-3665P4MEDIUMCVSS 6.8≤ 7.7.62015-07-03
CVE-2015-3665 [MEDIUM] CVE-2015-3665: QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary cod
QT Media Foundation in Apple QuickTime before 7.7.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, a different vulnerability than CVE-2015-3664 and CVE-2015-3669.
nvdapple
CVE-2007-0711P4CRITICALCVSS 9.3≤ 7.1.4v3.0+25 more2007-03-05
CVE-2007-0711 [CRITICAL] CWE-189 CVE-2007-0711: Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allow
Integer overflow in Apple QuickTime before 7.1.5, when installed on Windows operating systems, allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP video file.
nvd
CVE-2008-0036P3MEDIUMCVSS 6.8≤ 7.32008-01-16
CVE-2008-0036 [MEDIUM] CWE-119 CVE-2008-0036: Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via
Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding.
nvd
CVE-2008-1583P3MEDIUMCVSS 6.8≤ 7.4.52008-06-10
CVE-2008-1583 [MEDIUM] CVE-2008-1583: Heap-based buffer overflow in Apple QuickTime before 7.5 allows remote attackers to cause a denial o
Heap-based buffer overflow in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT image, a different vulnerability than CVE-2008-1581.
nvd
CVE-2008-3614P3MEDIUMCVSS 6.8≤ 7.5v7.0+18 more2008-09-11
CVE-2008-3614 [MEDIUM] CWE-189 CVE-2008-3614: Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbit
Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.
nvd
CVE-2006-1454P3MEDIUMCVSS 5.1v7.0.3v7.0.42006-05-12
CVE-2006-1454 [MEDIUM] CWE-119 CVE-2006-1454: Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrar
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.
nvd
CVE-2015-5785P4MEDIUMCVSS 6.8≤ 7.7.72015-08-25
CVE-2015-5785 [MEDIUM] CWE-119 CVE-2015-5785: Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5786.
nvdapple
CVE-2005-3711P4HIGHCVSS 7.5≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-3711 [HIGH] CWE-189 CVE-2005-3711: Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code v
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
nvd
CVE-2005-3708P4HIGHCVSS 7.5≤ 7.0.3v7.0+2 more2005-12-31
CVE-2005-3708 [HIGH] CVE-2005-3708: Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code v
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
nvd
CVE-2008-1023P4MEDIUMCVSS 6.8≤ 7.4.42008-04-04
CVE-2008-1023 [MEDIUM] CWE-119 CVE-2008-1023: Heap-based buffer overflow in Clip opcode parsing in Apple QuickTime before 7.4.5 on Windows allows
Heap-based buffer overflow in Clip opcode parsing in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file.
nvd
CVE-2008-1585P4MEDIUMCVSS 6.8≤ 7.4.52008-06-10
CVE-2008-1585 [MEDIUM] CWE-20 CVE-2008-1585: Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:
Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.
nvd
CVE-2006-1463P4MEDIUMCVSS 5.1v7.0.3v7.0.42006-05-12
CVE-2006-1463 [MEDIUM] CWE-119 CVE-2006-1463: Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrar
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.
nvd
CVE-2015-7092P4MEDIUMCVSS 6.6≤ 7.7.82016-01-09
CVE-2015-7092 [MEDIUM] CVE-2015-7092: Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of
Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7
nvdapple
CVE-2006-1249P4MEDIUMCVSS 6.8v7.0.3v7.0.42006-03-19
CVE-2006-1249 [MEDIUM] CWE-189 CVE-2006-1249: Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote
Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.
nvd
CVE-2007-4674P4MEDIUMCVSS 6.8v7.22007-11-27
CVE-2007-4674 [MEDIUM] CWE-189 CVE-2007-4674: An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary co
An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow.
nvd
CVE-2011-0210P4MEDIUMCVSS 6.8fixed in 7.7.02011-06-24
CVE-2011-0210 [MEDIUM] CWE-787 CVE-2011-0210: QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause
QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.
nvd
CVE-2006-4382P4MEDIUMCVSS 5.1≤ 7.1.2v5.0+14 more2006-09-12
CVE-2006-4382 [MEDIUM] CVE-2006-4382: Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to ex
Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie.
nvd