← Vulnerability feed

Vulnerability record · CVE-2017-9128 · published 12 June 2017

CVE-2017-9128: Libquicktime out-of-bounds read vulnerability

LLibquicktime · Libquicktime

The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.

6.5 CVSS 3.0 Medium EPSS 3.8% · top 10.3% CWE-125 · Out-of-bounds read
6.5CVSS 3.0 base score, v2 4.3
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2016-2399Libquicktime integer overflow vulnerabilityInteger overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or poss…EPSS 7.2%6.5CVE-2017-12143Libquicktime improper input validation vulnerabilityIn libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a deni…EPSS 1.0%6.5CVE-2017-12145Libquicktime improper input validation vulnerabilityIn libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of ser…EPSS 1.1%6.5CVE-2017-9122Libquicktime vulnerabilityThe quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumpt…EPSS 6.5%6.5CVE-2017-9123Libquicktime out-of-bounds read vulnerabilityThe lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read an…EPSS 3.8%6.5CVE-2017-9124Libquicktime null pointer dereference vulnerabilityThe quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and ap…EPSS 3.8%6.5CVE-2017-9125Libquicktime out-of-bounds read vulnerabilityThe lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over…EPSS 4.9%6.5CVE-2017-9126Libquicktime memory buffer overflow vulnerabilityThe quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overfl…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2017-9128), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.