CVE-2010-1819

4 documents4 sources
Severity
9.3CRITICAL
EPSS
3.8%
top 11.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 27
Latest updateMay 17

Description

Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) CoreVideo.dll, (2) CoreGraphics.dll, or (3) CoreAudioToolbox.dll that is located in the same folder as a .pic image file.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/quicktime7.6.7+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mfp7-p55f-gxr5: Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 72022-05-17
CVEList
CVE-2010-1819: Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 72013-12-27

💥Exploits & PoCs

1
Exploit-DB
HP Mercury Quality Center - ActiveX Control ProgColor Buffer Overflow (Metasploit)2010-04-30
CVE-2010-1819 (CRITICAL CVSS 9.3) | Untrusted search path vulnerability | cvebase.io