← Back

Quicktime

quicktime

Vendor: Apple • 246 CVEs

CVEs (246)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Quicktime
Apr 23, 2026
Jan 30, 2007
N/A· v4
N/A· v3
7.1 HIGH· v2
The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly...Show more
The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.Show less
1Apple
2Mac Os X
Quicktime
Apr 23, 2026
Jan 26, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly e...Show more
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT image with a malformed Alpha RGB (ARGB) record, which triggers memory corruption.Show less
1Apple
1Quicktime
Apr 23, 2026
Jan 5, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) th...Show more
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm.Show less
1Apple
1Quicktime
Apr 23, 2026
Jan 1, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
1Apple
1Quicktime
Apr 16, 2026
Sep 25, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parame...Show more
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.Show less
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object.
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file.
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381.
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image.
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie.
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie.
1Apple
1Quicktime
Apr 16, 2026
Sep 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally inclu...Show more
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.Show less
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.
1Apple
1Quicktime
Apr 16, 2026
May 12, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).