← Vulnerability feed

Vulnerability record · CVE-2005-2340 · published 31 December 2005

CVE-2005-2340: Apple quicktime memory buffer overflow vulnerability

Apple · Quicktime

Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.

7.5 CVSS 2.0 High EPSS 26% · top 2.1% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0392.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0398.html Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0402.html
http://docs.info.apple.com/article.html?artnum=303101 Patch
http://secunia.com/advisories/18370 PatchVendor Advisory
http://securityreason.com/securityalert/332
http://securitytracker.com/id?1015463 Patch
http://www.cirt.dk/advisories/cirt-41-advisory.pdf Vendor Advisory
http://www.kb.cert.org/vuls/id/629845 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/687201 PatchThird Party AdvisoryUS Government Resource
http://www.osvdb.org/22333 Patch
http://www.osvdb.org/22334 Patch
http://www.osvdb.org/22335 Patch
http://www.securityfocus.com/archive/1/421547/100/0/threaded
http://www.securityfocus.com/archive/1/421566/100/0/threaded
http://www.securityfocus.com/bid/16202 Patch
http://www.securityfocus.com/bid/16212 Exploit
http://www.us-cert.gov/cas/techalerts/TA06-011A.html PatchThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/0128 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24054
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0392.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0398.html Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0402.html
http://docs.info.apple.com/article.html?artnum=303101 Patch
http://secunia.com/advisories/18370 PatchVendor Advisory
http://securityreason.com/securityalert/332
http://securitytracker.com/id?1015463 Patch
http://www.cirt.dk/advisories/cirt-41-advisory.pdf Vendor Advisory
http://www.kb.cert.org/vuls/id/629845 PatchThird Party AdvisoryUS Government Resource
http://www.kb.cert.org/vuls/id/687201 PatchThird Party AdvisoryUS Government Resource
http://www.osvdb.org/22333 Patch
http://www.osvdb.org/22334 Patch
http://www.osvdb.org/22335 Patch
http://www.securityfocus.com/archive/1/421547/100/0/threaded
http://www.securityfocus.com/archive/1/421566/100/0/threaded
http://www.securityfocus.com/bid/16202 Patch
http://www.securityfocus.com/bid/16212 Exploit
http://www.us-cert.gov/cas/techalerts/TA06-011A.html PatchThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/0128 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24054

Track CVE-2005-2340 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6238Apple quicktime vulnerabilityUnspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably…EPSS 3.9%10.0CVE-2007-0462Apple quicktime vulnerabilityThe _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote at…EPSS 6.7%9.8CVE-2011-3428Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.EPSS 2.0%9.3CVE-2014-4979Apple quicktime memory buffer overflow vulnerabilityApple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and…EPSS 3.6%9.3CVE-2014-1243Apple quicktime memory buffer overflow vulnerabilityApple QuickTime before 7.7.5 does not initialize an unspecified pointer, which allows remote attackers to execute arbitrary code or cause a denial of…EPSS 3.6%9.3CVE-2014-1244Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…EPSS 4.1%9.3CVE-2014-1245Apple quicktime vulnerabilityInteger signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application …EPSS 3.6%9.3CVE-2014-1246Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2005-2340), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.