CVE-2010-1818

The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
applequicktime
6.0
applequicktime
6.0.0
applequicktime
6.0.1
applequicktime
6.0.2
applequicktime
6.1
applequicktime
6.1.0
applequicktime
6.1.1
applequicktime
6.2.0
applequicktime
6.3.0
applequicktime
6.4.0
applequicktime
6.5
applequicktime
6.5.0
applequicktime
6.5.1
applequicktime
6.5.2
applequicktime
7.0
applequicktime
7.0.0
applequicktime
7.0.1
applequicktime
7.0.2
applequicktime
7.0.3
applequicktime
7.0.4
applequicktime
7.1
applequicktime
7.1.0
applequicktime
7.1.1
applequicktime
7.1.2
applequicktime
7.1.3
applequicktime
7.1.4
applequicktime
7.1.5
applequicktime
7.1.6
applequicktime
7.2
applequicktime
7.2.0
applequicktime
7.2.1
applequicktime
7.3
applequicktime
7.3.0
applequicktime
7.3.1
applequicktime
7.3.1.70
applequicktime
7.4
applequicktime
7.4.0
applequicktime
7.4.1
applequicktime
7.4.5
applequicktime
7.5.0
applequicktime
7.5.5
applequicktime
7.6.0
applequicktime
7.6.1
applequicktime
7.6.2
applequicktime
7.6.5
applequicktime
7.6.6
applequicktime
7.6.7
𝑥
= Vulnerable software versions