Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Libquicktime Subscribe
Total 10 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-9128 1 Libquicktime 1 Libquicktime 2020-09-28 4.3 MEDIUM 6.5 MEDIUM
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.
CVE-2017-9125 1 Libquicktime 1 Libquicktime 2020-09-28 4.3 MEDIUM 6.5 MEDIUM
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.
CVE-2017-9126 1 Libquicktime 1 Libquicktime 2020-09-28 4.3 MEDIUM 6.5 MEDIUM
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
CVE-2017-9127 1 Libquicktime 1 Libquicktime 2020-09-28 4.3 MEDIUM 6.5 MEDIUM
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
CVE-2017-9122 1 Libquicktime 1 Libquicktime 2020-09-28 7.1 HIGH 6.5 MEDIUM
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
CVE-2017-9123 1 Libquicktime 1 Libquicktime 2020-09-28 4.3 MEDIUM 6.5 MEDIUM
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
CVE-2017-9124 1 Libquicktime 1 Libquicktime 2020-09-28 4.3 MEDIUM 6.5 MEDIUM
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
CVE-2016-2399 1 Libquicktime 1 Libquicktime 2017-11-03 6.8 MEDIUM 7.8 HIGH
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.
CVE-2017-12143 1 Libquicktime 1 Libquicktime 2017-08-03 4.3 MEDIUM 6.5 MEDIUM
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-12145 1 Libquicktime 1 Libquicktime 2017-08-03 4.3 MEDIUM 6.5 MEDIUM
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.