Vulnerabilities > Apple > Quicktime > 7.0.4

DATE CVE VULNERABILITY TITLE RISK
2010-12-09 CVE-2010-3800 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.
network
apple CWE-119
critical
9.3
2010-12-09 CVE-2010-1508 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Track Header (aka tkhd) atoms.
network
apple microsoft CWE-119
critical
9.3
2010-12-09 CVE-2010-0530 Permissions, Privileges, and Access Controls vulnerability in Apple Quicktime
Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive information by reading files in this directory.
local
low complexity
apple microsoft CWE-264
2.1
2010-08-31 CVE-2010-1818 Access of Uninitialized Pointer vulnerability in Apple Quicktime
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.
network
apple CWE-824
critical
9.3
2010-08-16 CVE-2010-1799 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
network
apple microsoft CWE-119
critical
9.3
2010-03-31 CVE-2010-0536 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.
network
apple microsoft CWE-119
critical
9.3
2010-03-31 CVE-2010-0529 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.
network
apple microsoft CWE-119
critical
9.3
2010-03-31 CVE-2010-0528 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.
network
apple microsoft CWE-119
critical
9.3
2010-03-31 CVE-2010-0527 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.
network
apple microsoft CWE-189
critical
9.3
2009-09-10 CVE-2009-2799 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.
network
apple CWE-119
critical
9.3