Libquicktime is a multimedia library for parsing and handling QuickTime media files, a modestly represented but strategically important component across media-processing and multimedia-playback applications. The vendor's vulnerability profile is anchored in frequently available public exploit code and recurs through memory-handling and input-validation weakness classes—out-of-bounds reads, integer overflows, improper buffer restrictions, and infinite loops—that arise from the complexity of parsing untrusted media containers and reflect the attack surface inherent to file-format parsers. Defenders should prioritize patching this library in any media-processing pipeline or embedded playback system, particularly where untrusted or user-supplied media may be processed; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libquicktime over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2399HIGH Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified imp | Jan 30, 2017 | 7.8 | 39 | NO | YES |
CVE-2017-9122MEDIUM The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file. | Jun 12, 2017 | 6.5 | 34 | NO | YES |
CVE-2017-9127MEDIUM The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application cr | Jun 12, 2017 | 6.5 | 33 | NO | YES |
CVE-2017-9125MEDIUM The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file. | Jun 12, 2017 | 6.5 | 33 | NO | YES |
CVE-2017-9128MEDIUM The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) | Jun 12, 2017 | 6.5 | 32 | NO | YES |
CVE-2017-9126MEDIUM The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a | Jun 12, 2017 | 6.5 | 32 | NO | YES |
CVE-2017-9124MEDIUM The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted | Jun 12, 2017 | 6.5 | 32 | NO | YES |
CVE-2017-9123MEDIUM The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a craf | Jun 12, 2017 | 6.5 | 32 | NO | YES |
CVE-2017-12145MEDIUM In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file. | Aug 2, 2017 | 6.5 | 21 | NO | NO |
CVE-2017-12143MEDIUM In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted fil | Aug 2, 2017 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libquicktime.
Media articles that mention a CVE ID that affects a product developed by Libquicktime — matched by CVE ID, not by vendor name.