Lucene search

K
cveAppleCVE-2010-0528
HistoryMar 31, 2010 - 6:30 p.m.

CVE-2010-0528

2010-03-3118:30:00
CWE-119
apple
web.nvd.nist.gov
32
cve-2010-0528
apple quicktime
remote code execution
memory corruption
denial of service
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.06

Percentile

93.6%

Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.

Affected configurations

Nvd
Node
applequicktimeRange7.6.0-windows
OR
applequicktimeMatch7.0.0-windows
OR
applequicktimeMatch7.0.1-windows
OR
applequicktimeMatch7.0.2-windows
OR
applequicktimeMatch7.0.3-windows
OR
applequicktimeMatch7.0.4-windows
OR
applequicktimeMatch7.1.0-windows
OR
applequicktimeMatch7.1.1-windows
OR
applequicktimeMatch7.1.2-windows
OR
applequicktimeMatch7.1.3-windows
OR
applequicktimeMatch7.1.4-windows
OR
applequicktimeMatch7.1.5-windows
OR
applequicktimeMatch7.1.6-windows
OR
applequicktimeMatch7.2.0-windows
OR
applequicktimeMatch7.2.1-windows
OR
applequicktimeMatch7.3.0-windows
OR
applequicktimeMatch7.3.1-windows
OR
applequicktimeMatch7.4.0-windows
OR
applequicktimeMatch7.4.1-windows
OR
applequicktimeMatch7.4.5-windows
OR
applequicktimeMatch7.5.0-windows
OR
applequicktimeMatch7.5.5-windows
OR
applequicktimeMatch7.6.1-windows
OR
applequicktimeMatch7.6.6-windows
AND
microsoftwindows_7
OR
microsoftwindows_vista
OR
microsoftwindows_xpsp2
VendorProductVersionCPE
applequicktime*cpe:2.3:a:apple:quicktime:*:-:windows:*:*:*:*:*
applequicktime7.0.0cpe:2.3:a:apple:quicktime:7.0.0:-:windows:*:*:*:*:*
applequicktime7.0.1cpe:2.3:a:apple:quicktime:7.0.1:-:windows:*:*:*:*:*
applequicktime7.0.2cpe:2.3:a:apple:quicktime:7.0.2:-:windows:*:*:*:*:*
applequicktime7.0.3cpe:2.3:a:apple:quicktime:7.0.3:-:windows:*:*:*:*:*
applequicktime7.0.4cpe:2.3:a:apple:quicktime:7.0.4:-:windows:*:*:*:*:*
applequicktime7.1.0cpe:2.3:a:apple:quicktime:7.1.0:-:windows:*:*:*:*:*
applequicktime7.1.1cpe:2.3:a:apple:quicktime:7.1.1:-:windows:*:*:*:*:*
applequicktime7.1.2cpe:2.3:a:apple:quicktime:7.1.2:-:windows:*:*:*:*:*
applequicktime7.1.3cpe:2.3:a:apple:quicktime:7.1.3:-:windows:*:*:*:*:*
Rows per page:
1-10 of 271

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.06

Percentile

93.6%