CVE-2010-1880

Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:microsoft:directx:9.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:directx:9.0a:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:directx:9.0b:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:directx:9.0c:*:*:*:*:*:*:*
OR cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:itanium:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:x32:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2008:*:*:x64:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:sp2:x64:*:*:*:*:*

History

07 Dec 2023, 18:38

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_vista:*:sp1:x64:*:*:*:*:*

Information

Published : 2010-06-08 22:30

Updated : 2024-02-04 17:54


NVD link : CVE-2010-1880

Mitre link : CVE-2010-1880

CVE.ORG link : CVE-2010-1880


JSON object : View

Products Affected

microsoft

  • windows_2003_server
  • windows_xp
  • directx
  • windows_server_2008
  • windows_2000
  • windows_vista
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')