9.3
CVSSv2

CVE-2010-1818

Published: 31/08/2010 Updated: 27/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x prior to 7.6.8, and other versions allows remote malicious users to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.

Vulnerable Product Search on Vulmon Subscribe to Product

apple quicktime 6.0.1

apple quicktime 6.0.2

apple quicktime 6.5

apple quicktime 6.5.0

apple quicktime 7.0.3

apple quicktime 7.0.4

apple quicktime 7.1.6

apple quicktime 7.2

apple quicktime 7.4

apple quicktime 7.4.0

apple quicktime 7.6.2

apple quicktime 7.6.5

apple quicktime 7.6.6

apple quicktime 6.1.1

apple quicktime 6.2.0

apple quicktime 7.0

apple quicktime 7.0.0

apple quicktime 7.1.2

apple quicktime 7.1.3

apple quicktime 7.3

apple quicktime 7.3.0

apple quicktime 7.5.0

apple quicktime 7.5.5

apple quicktime 6.1

apple quicktime 6.1.0

apple quicktime 6.5.1

apple quicktime 6.5.2

apple quicktime 7.1

apple quicktime 7.1.0

apple quicktime 7.1.1

apple quicktime 7.2.0

apple quicktime 7.2.1

apple quicktime 7.4.1

apple quicktime 7.4.5

apple quicktime 7.6.7

apple quicktime 6.0

apple quicktime 6.0.0

apple quicktime 6.3.0

apple quicktime 6.4.0

apple quicktime 7.0.1

apple quicktime 7.0.2

apple quicktime 7.1.4

apple quicktime 7.1.5

apple quicktime 7.3.1

apple quicktime 7.3.1.70

apple quicktime 7.6.0

apple quicktime 7.6.1

Exploits

## # $Id: apple_quicktime_marshaled_punkrb 11513 2011-01-08 00:25:44Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'm ...
Original Source: reversemodecom/indexphp?option=com_content&task=view&id=69&Itemid=1 Victim prerequisites: * Internet Explorer * XP,Vista,W7 * Apple Quicktime 7x, 6x ( 2004 versions are also vulnerable, older versions not checked ) 1 Victim is enticed into visiting, by any mean, a specially crafted webpage 2 Attacker' ...