VendorsApplequicktime7.0
Vulnerabilities

Apple Quicktime 7.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

95CVEs
CVE-2006-4382
Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie.
Published 2006-09-12 · Modified
5.1EPSS 0.070
CVE-2006-4385
Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image.
Published 2006-09-12 · Modified
5.1EPSS 0.067
CVE-2006-4386
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381.
Published 2006-09-12 · Modified
5.1EPSS 0.062
CVE-2006-4388
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file.
Published 2006-09-12 · Modified
5.1EPSS 0.059
CVE-2006-1460
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.
Published 2006-05-12 · Modified
5.1EPSS 0.055
CVE-2006-1461
Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.
Published 2006-05-12 · Modified
5.1EPSS 0.052
CVE-2006-4381
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie.
Published 2006-09-12 · Modified
5.1EPSS 0.046
CVE-2005-2756
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
Published 2005-11-05 · Modified
5.1EPSS 0.042
CVE-2005-2754
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
Published 2005-11-05 · Modified
5.1EPSS 0.021
CVE-2005-2753
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
Published 2005-11-05 · Modified
5.1EPSS 0.021
CVE-2005-1579
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.
Published 2005-05-14 · Modified
5.0EPSS 0.020
CVE-2007-2402
QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.
Published 2007-07-15 · Modified
4.3EPSS 0.028
CVE-2008-3629
Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.
Published 2008-09-10 · Modified
4.3EPSS 0.018
CVE-2005-2755
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
Published 2005-11-05 · Modified
2.6EPSS 0.018
CVE-2010-0530
Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.
Published 2010-12-09 · Modified
2.1EPSS 0.004
← Prev3 / 3