Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Quicktime | Apple | * | 7.4.4 (including) |