CVE-2017-9127 describes a heap-based buffer overflow vulnerability in the libquicktime 1.2.4 library, specifically within the quicktime_user_atoms_read_atom function, which can be triggered by a specially crafted MP4 file. This flaw carries a CVSSv3 score of 6.5 (Medium), indicating it can lead to a denial of service (application crash) with low attack complexity, requiring user interaction (e.g., opening a malicious file) but no authentication. While not actively exploited in the wild and not listed on CISA's KEV catalog, a public proof-of-concept exploit exists on ExploitDB, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.4CPE matchmatch criteria | cpe:2.3:a:libquicktime:libquicktime:1.2.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.