
Six of the vulnerabilities could allow attackers to remotely execute code on the targeted machine.
Three of the remote code execution vulnerabilities could be exploited when the user launches a specially-crafted movie file.
Two are exploited by way of malformed Pict files, and one can be targeted by way of a specially-crafted QuickTime VR file.
The update also addresses a flaw in the way QuickTime handles untrusted Java applets. Apple said that this could allow an attacker to run malicious Java code on the user's machine.
The update fixes the issue by preventing untrusted applets from running QuickTime's Java components.
Users can obtain the update through Apple's Software Update utility or the Apple Downloads site.