Lucene search

K
cveAppleCVE-2010-0529
HistoryMar 31, 2010 - 6:30 p.m.

CVE-2010-0529

2010-03-3118:30:00
CWE-119
apple
web.nvd.nist.gov
33
cve-2010-0529
apple quicktime
windows
buffer overflow
remote code execution
denial of service
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.94

Percentile

99.2%

Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.

Affected configurations

Nvd
Node
applequicktimeRange7.6.0-windows
OR
applequicktimeMatch7.0.0-windows
OR
applequicktimeMatch7.0.1-windows
OR
applequicktimeMatch7.0.2-windows
OR
applequicktimeMatch7.0.3-windows
OR
applequicktimeMatch7.0.4-windows
OR
applequicktimeMatch7.1.0-windows
OR
applequicktimeMatch7.1.1-windows
OR
applequicktimeMatch7.1.2-windows
OR
applequicktimeMatch7.1.3-windows
OR
applequicktimeMatch7.1.4-windows
OR
applequicktimeMatch7.1.5-windows
OR
applequicktimeMatch7.1.6-windows
OR
applequicktimeMatch7.2.0-windows
OR
applequicktimeMatch7.2.1-windows
OR
applequicktimeMatch7.3.0-windows
OR
applequicktimeMatch7.3.1-windows
OR
applequicktimeMatch7.4.0-windows
OR
applequicktimeMatch7.4.1-windows
OR
applequicktimeMatch7.4.5-windows
OR
applequicktimeMatch7.5.0-windows
OR
applequicktimeMatch7.5.5-windows
AND
microsoftwindows_7
OR
microsoftwindows_vista
OR
microsoftwindows_xpsp2
VendorProductVersionCPE
applequicktime*cpe:2.3:a:apple:quicktime:*:-:windows:*:*:*:*:*
applequicktime7.0.0cpe:2.3:a:apple:quicktime:7.0.0:-:windows:*:*:*:*:*
applequicktime7.0.1cpe:2.3:a:apple:quicktime:7.0.1:-:windows:*:*:*:*:*
applequicktime7.0.2cpe:2.3:a:apple:quicktime:7.0.2:-:windows:*:*:*:*:*
applequicktime7.0.3cpe:2.3:a:apple:quicktime:7.0.3:-:windows:*:*:*:*:*
applequicktime7.0.4cpe:2.3:a:apple:quicktime:7.0.4:-:windows:*:*:*:*:*
applequicktime7.1.0cpe:2.3:a:apple:quicktime:7.1.0:-:windows:*:*:*:*:*
applequicktime7.1.1cpe:2.3:a:apple:quicktime:7.1.1:-:windows:*:*:*:*:*
applequicktime7.1.2cpe:2.3:a:apple:quicktime:7.1.2:-:windows:*:*:*:*:*
applequicktime7.1.3cpe:2.3:a:apple:quicktime:7.1.3:-:windows:*:*:*:*:*
Rows per page:
1-10 of 251

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.1

Confidence

High

EPSS

0.94

Percentile

99.2%