← Vulnerability feed

Vulnerability record · CVE-2011-0257 · published 15 August 2011

CVE-2011-0257: Apple QuickTime PICT PnSize opcode stack buffer overflow

Apple · Quicktime

Apple QuickTime before 7.7 has an integer signedness error when parsing the PnSize opcode in a PICT file, which leads to a stack-based buffer overflow. A crafted PICT file can crash the application or allow remote code execution. The flaw matters because PICT files are commonly opened through browsers, mail clients and file previews, so a single malicious image can reach the vulnerable parser.

9.3 CVSS 2.0 High EPSS 60% · top 0.9% CWE-189 · CWE-189
9.3CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityThe CVSS 2.0 score is 9.3 with complete confidentiality, integrity and availability impact, public exploit code exists, and EPSS is near the top percentile, though the flaw requires user interaction and affects an aging product.

What it is

Apple QuickTime before 7.7 has an integer signedness error when parsing the PnSize opcode in a PICT file, which leads to a stack-based buffer overflow. A crafted PICT file can crash the application or allow remote code execution. The flaw matters because PICT files are commonly opened through browsers, mail clients and file previews, so a single malicious image can reach the vulnerable parser.

Impact

An attacker can execute arbitrary code in the context of the user running QuickTime, or at minimum crash the application. Successful exploitation gives full control over confidentiality, integrity and availability on the affected host.

Attack surface

The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N), meaning the victim must open or preview a crafted PICT file. No credentials are required, but user interaction with the malicious file is needed.

Exploitation

CVE-2011-0257 is not listed in CISA KEV, but EPSS shows a 30-day probability of about 0.60 (99th percentile), and a public Exploit-DB entry (17777) plus a ZDI advisory exist, indicating exploit code is publicly available.

What to do

  • Upgrade Apple QuickTime to version 7.7 or later, which contains the vendor fix described in Apple advisory HT4826.
  • If QuickTime cannot be updated or is no longer needed, uninstall it or disable PICT handling and browser/plugin integration.
  • Block or strip PICT files at email and web gateways where business use does not require them.
  • Restrict execution of QuickTime and its browser plugins to trusted users and apply least-privilege accounts.
  • Monitor vendor advisories for any further QuickTime fixes, since this product line has a history of parser flaws.

Detection

  • Search endpoint logs and EDR telemetry for QuickTime processes (QuickTimePlayer.exe, qttask.exe) spawning child processes or writing executables after opening media files.
  • Alert on PICT files (.pct, .pict) delivered via email attachments or web downloads, especially from external senders.
  • Use file inspection or YARA rules to flag PICT files containing malformed PnSize opcodes and oversized size fields.
  • Correlate QuickTime crash reports (stack overflow in the PICT parser) with subsequent suspicious process activity on the same host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0257 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-6238Apple quicktime vulnerabilityUnspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably…EPSS 3.9%10.0CVE-2007-0462Apple quicktime vulnerabilityThe _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote at…EPSS 6.7%9.8CVE-2011-3428Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code.EPSS 2.0%9.3CVE-2014-4979Apple quicktime memory buffer overflow vulnerabilityApple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and…EPSS 3.6%9.3CVE-2014-1243Apple quicktime memory buffer overflow vulnerabilityApple QuickTime before 7.7.5 does not initialize an unspecified pointer, which allows remote attackers to execute arbitrary code or cause a denial of…EPSS 3.6%9.3CVE-2014-1244Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…EPSS 4.1%9.3CVE-2014-1245Apple quicktime vulnerabilityInteger signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application …EPSS 3.6%9.3CVE-2014-1246Apple quicktime memory buffer overflow vulnerabilityBuffer overflow in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) vi…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2011-0257), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.