Lucene search

K
cveMitreCVE-2004-1481
HistoryFeb 13, 2005 - 5:00 a.m.

CVE-2004-1481

2005-02-1305:00:00
mitre
web.nvd.nist.gov
34
cve-2004-1481
realplayer
realone player
integer overflow
remote code execution
smil file
buffer overflow

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

High

EPSS

0.26

Percentile

96.7%

Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.

Affected configurations

Nvd
Node
realnetworkshelix_playerMatch1.0linux
OR
realnetworksrealone_playerMatch1.0
OR
realnetworksrealone_playerMatch2.0
OR
realnetworksrealone_playerMatch9.0.0.288macos
OR
realnetworksrealone_playerMatch9.0.0.297macos
OR
realnetworksrealplayerMatch-enterprise
OR
realnetworksrealplayerMatch8.0
OR
realnetworksrealplayerMatch8.0mac_os_x
OR
realnetworksrealplayerMatch8.0unix
OR
realnetworksrealplayerMatch10.0
OR
realnetworksrealplayerMatch10.0linux
OR
realnetworksrealplayerMatch10.0de
OR
realnetworksrealplayerMatch10.0en
OR
realnetworksrealplayerMatch10.0ja
OR
realnetworksrealplayerMatch10.0beta
OR
realnetworksrealplayerMatch10.0betamac_os_x
OR
realnetworksrealplayerMatch10.0_6.0.12.690
OR
realnetworksrealplayerMatch10.5
OR
realnetworksrealplayerMatch10.5_6.0.12.1016beta
OR
realnetworksrealplayerMatch10.5_6.0.12.1040
VendorProductVersionCPE
realnetworkshelix_player1.0cpe:2.3:a:realnetworks:helix_player:1.0:*:*:*:*:linux:*:*
realnetworksrealone_player1.0cpe:2.3:a:realnetworks:realone_player:1.0:*:*:*:*:*:*:*
realnetworksrealone_player2.0cpe:2.3:a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*
realnetworksrealone_player9.0.0.288cpe:2.3:a:realnetworks:realone_player:9.0.0.288:*:*:*:*:macos:*:*
realnetworksrealone_player9.0.0.297cpe:2.3:a:realnetworks:realone_player:9.0.0.297:*:*:*:*:macos:*:*
realnetworksrealplayer-cpe:2.3:a:realnetworks:realplayer:-:*:*:*:enterprise:*:*:*
realnetworksrealplayer8.0cpe:2.3:a:realnetworks:realplayer:8.0:*:*:*:*:*:*:*
realnetworksrealplayer8.0cpe:2.3:a:realnetworks:realplayer:8.0:*:*:*:*:mac_os_x:*:*
realnetworksrealplayer8.0cpe:2.3:a:realnetworks:realplayer:8.0:*:*:*:*:unix:*:*
realnetworksrealplayer10.0cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

High

EPSS

0.26

Percentile

96.7%