Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libquicktime

First CVE: Jan 30, 2017Active for: 9 yearsTotal CVEs: 10
39.5
VTI Score
Medium

Libquicktime is a multimedia library for parsing and handling QuickTime media files, a modestly represented but strategically important component across media-processing and multimedia-playback applications. The vendor's vulnerability profile is anchored in frequently available public exploit code and recurs through memory-handling and input-validation weakness classes—out-of-bounds reads, integer overflows, improper buffer restrictions, and infinite loops—that arise from the complexity of parsing untrusted media containers and reflect the attack surface inherent to file-format parsers. Defenders should prioritize patching this library in any media-processing pipeline or embedded playback system, particularly where untrusted or user-supplied media may be processed; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
10.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libquicktime over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2017
9 years ago
Most Recent CVE
Aug 2, 2017
3,278 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-2399HIGH
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified imp
Jan 30, 20177.839NOYES
CVE-2017-9122MEDIUM
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
Jun 12, 20176.534NOYES
CVE-2017-9127MEDIUM
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application cr
Jun 12, 20176.533NOYES
CVE-2017-9125MEDIUM
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.
Jun 12, 20176.533NOYES
CVE-2017-9128MEDIUM
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash)
Jun 12, 20176.532NOYES
CVE-2017-9126MEDIUM
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a
Jun 12, 20176.532NOYES
CVE-2017-9124MEDIUM
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted
Jun 12, 20176.532NOYES
CVE-2017-9123MEDIUM
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a craf
Jun 12, 20176.532NOYES
CVE-2017-12145MEDIUM
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.
Aug 2, 20176.521NONO
CVE-2017-12143MEDIUM
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted fil
Aug 2, 20176.517NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
90%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required10 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
80.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libquicktime.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libquicktime — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libquicktime's Products

View all 1 CNAs →

Top CWEs