Quicktime
Vendor:
First CVE: May 3, 2001 · Active for 25 years
250
Total CVEs
More Total CVEs than 100% of tracked products
14.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Quicktime over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2001
25 years ago
Most Recent CVE
Jul 7, 2017
3,304 days ago
CVE Severity & Scoring
Quicktime250 CVEs
41%
58%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (4.0%)
Network1 (0.4%)
Unknown239 (95.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (4.4%)
High0 (0.0%)
Unknown239 (95.6%)
User Interaction
None1 (0.4%)
Unknown239 (95.6%)
Required10 (4.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (4.4%)
Unknown239 (95.6%)
Top CVEs
Signals from CVEs in this product scope (250 CVEs).
250 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-0257HIGH Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcod | Aug 15, 2011 | 9.3 | 81 | NO | YES |
CVE-2010-1818HIGH The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Mars | Aug 31, 2010 | 9.3 | 72 | NO | YES |
CVE-2012-3752HIGH Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted style elem | Nov 9, 2012 | 9.3 | 69 | NO | YES |
CVE-2012-3753HIGH Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIME | Nov 9, 2012 | 9.3 | 68 | NO | YES |
CVE-2012-0663HIGH Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbitrary code or cause a denial of service (application crash) v | May 16, 2012 | 9.3 | 65 | NO | YES |
CVE-2010-1799HIGH Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of ser | Aug 16, 2010 | 9.3 | 65 | NO | YES |
CVE-2007-6166HIGH Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) ser | Nov 29, 2007 | 9.3 | 65 | NO | YES |
CVE-2007-0015MEDIUM Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI. | Jan 1, 2007 | 6.8 | 65 | NO | YES |
CVE-2013-1017HIGH Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie | May 24, 2013 | 9.3 | 59 | NO | YES |
CVE-2007-4676HIGH Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) | Nov 7, 2007 | 9.3 | 51 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (250 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
9 CVEs
3.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
23 CVEs
9.2% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (250 CVEs).
Media Mentions
Signals from CVEs in this product scope (250 CVEs).
Top CNAs Publishing CVEs For Quicktime
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.7.3 | 9 | 9.3 | 3.9% | 0 | 0 |
| 7.7.2 | 21 | 9.3 | 5.6% | 0 | 1 |
| 7.71.80.42 | 9 | 9.3 | 3.9% | 0 | 0 |
| 7.7.1 | 30 | 9.3 | 7.6% | 0 | 4 |
| 7.70.80.34 | 9 | 9.3 | 3.9% | 0 | 0 |
| 7.7.0 | 40 | 9.3 | 7.4% | 0 | 5 |
| 7.69.80.9 | 19 | 9.3 | 5.5% | 0 | 1 |
| 7.6.9 | 45 | 9.3 | 7.1% | 0 | 5 |
| 7.68.75.0 | 19 | 9.3 | 5.5% | 0 | 1 |
| 7.6.8 | 56 | 9.3 | 7.6% | 0 | 6 |
| 7.67.75.0 | 23 | 9.3 | 7.8% | 0 | 2 |
| 7.6.7 | 63 | 9.2 | 7.8% | 0 | 7 |
| 7.66.71.0 | 23 | 9.3 | 7.8% | 0 | 2 |
| 7.6.6 | 66 | 9.2 | 8.1% | 0 | 8 |
| 7.65.17.80 | 19 | 9.3 | 5.5% | 0 | 1 |
| 7.6.5 | 64 | 9.2 | 7.8% | 0 | 7 |
| 7.64.17.73 | 19 | 9.3 | 5.5% | 0 | 1 |
| 7.62.14.0 | 19 | 9.3 | 5.5% | 0 | 1 |
| 7.6.2 | 65 | 9.2 | 8.2% | 0 | 8 |
| 7.6.1 | 70 | 9.2 | 8.2% | 0 | 8 |