← Back

Quicktime

quicktime

Vendor: Apple • 246 CVEs

CVEs (246)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
1Quicktime
Apr 29, 2026
Dec 9, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.
1Apple
1Quicktime
Apr 29, 2026
Dec 9, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.
1Apple
1Quicktime
Apr 29, 2026
Dec 9, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.
1Apple
1Quicktime
Apr 29, 2026
Dec 9, 2010
N/A· v4
N/A· v3
2.1 LOW· v2
Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory...Show more
Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.Show less
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file.
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file.
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that causes an image samp...Show more
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that causes an image sample transformation to scale a sprite outside a buffer boundary.Show less
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file.
1Apple
3Mac Os X
Mac Os X ServerQuicktime
Apr 29, 2026
Nov 16, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (applicat...Show more
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 file.Show less
1Apple
1Quicktime
Apr 29, 2026
Aug 31, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unm...Show more
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.Show less
1Apple
1Quicktime
Apr 29, 2026
Aug 16, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted m...Show more
Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.Show less
1Apple
1Quicktime
Apr 29, 2026
Mar 31, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.
1Apple
1Quicktime
Apr 29, 2026
Mar 31, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat o...Show more
Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.Show less
1Apple
1Quicktime
Apr 29, 2026
Mar 31, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malfor...Show more
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.Show less
1Apple
1Quicktime
Apr 29, 2026
Mar 31, 2010
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
1Apple
1Quicktime
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.
1Apple
1Quicktime
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
1Apple
1Quicktime
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file.
1Apple
1Quicktime
Apr 23, 2026
Sep 10, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file.