Quicktime

Vendor:

First CVE: May 3, 2001 · Active for 25 years

250
Total CVEs
More Total CVEs than 100% of tracked products
14.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Quicktime over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2001
25 years ago
Most Recent CVE
Jul 7, 2017
3,304 days ago

CVE Severity & Scoring

Quicktime250 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local10 (4.0%)
Network1 (0.4%)
Unknown239 (95.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (4.4%)
High0 (0.0%)
Unknown239 (95.6%)
User Interaction
None1 (0.4%)
Unknown239 (95.6%)
Required10 (4.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (4.4%)
Unknown239 (95.6%)

Top CVEs

Signals from CVEs in this product scope (250 CVEs).

250 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcod
Aug 15, 20119.381NOYES
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Mars
Aug 31, 20109.372NOYES
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style elem
Nov 9, 20129.369NOYES
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME
Nov 9, 20129.368NOYES
Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) v
May 16, 20129.365NOYES
Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of ser
Aug 16, 20109.365NOYES
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) ser
Nov 29, 20079.365NOYES
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
Jan 1, 20076.865NOYES
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie
May 24, 20139.359NOYES
Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074)
Nov 7, 20079.351NONO

Exploit Exposure

Signals from CVEs in this product scope (250 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
9 CVEs
3.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
23 CVEs
9.2% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (250 CVEs).

Media Mentions

Signals from CVEs in this product scope (250 CVEs).

Top CNAs Publishing CVEs For Quicktime

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.7.399.33.9%00
7.7.2219.35.6%01
7.71.80.4299.33.9%00
7.7.1309.37.6%04
7.70.80.3499.33.9%00
7.7.0409.37.4%05
7.69.80.9199.35.5%01
7.6.9459.37.1%05
7.68.75.0199.35.5%01
7.6.8569.37.6%06
7.67.75.0239.37.8%02
7.6.7639.27.8%07
7.66.71.0239.37.8%02
7.6.6669.28.1%08
7.65.17.80199.35.5%01
7.6.5649.27.8%07
7.64.17.73199.35.5%01
7.62.14.0199.35.5%01
7.6.2659.28.2%08
7.6.1709.28.2%08