The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.
Threat-Mapped Scoring
Score: 1.8
Priority: P4 - Informational (Low)
S9 – Sabotage of System/App
EPSS
Score: 0.76511Percentile:
0.98876
CVSS Scoring
CVSS v2 Score: 9.3
Severity:
Mapped CWE(s)
CWE-824
: Access of Uninitialized Pointer
Affected Products
cpe:2.3:a:apple:quicktime:6.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:6.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.1.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.3.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.3.1.70:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.4.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.5.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.6.5:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.6.6:*:*:*:*:*:*:*
cpe:2.3:a:apple:quicktime:7.6.7:*:*:*:*:*:*:*
← Back to Home
BrownCoat Threat Intelligence Platform | 2025 Steve Gray — You Can’t Take the Sky from Me