Lucene search

K
cveFlexeraCVE-2010-0120
HistoryAug 30, 2010 - 8:00 p.m.

CVE-2010-0120

2010-08-3020:00:01
CWE-119
flexera
web.nvd.nist.gov
33
cve-2010-0120
realplayer
buffer overflow
remote code execution
nvd
security vulnerability
heap-based overflow
windows

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.4

Confidence

Low

EPSS

0.836

Percentile

98.5%

Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content.

Affected configurations

Nvd
Node
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.1
AND
microsoftwindows
Node
realnetworksrealplayer_spMatch1.0.0
OR
realnetworksrealplayer_spMatch1.0.1
OR
realnetworksrealplayer_spMatch1.0.2
OR
realnetworksrealplayer_spMatch1.0.5
OR
realnetworksrealplayer_spMatch1.1
OR
realnetworksrealplayer_spMatch1.1.1
OR
realnetworksrealplayer_spMatch1.1.2
OR
realnetworksrealplayer_spMatch1.1.3
OR
realnetworksrealplayer_spMatch1.1.4
AND
microsoftwindows
VendorProductVersionCPE
realnetworksrealplayer11.0cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*
realnetworksrealplayer11.1cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.0cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.1cpe:2.3:a:realnetworks:realplayer_sp:1.0.1:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.2cpe:2.3:a:realnetworks:realplayer_sp:1.0.2:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.5cpe:2.3:a:realnetworks:realplayer_sp:1.0.5:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.1cpe:2.3:a:realnetworks:realplayer_sp:1.1:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.1.1cpe:2.3:a:realnetworks:realplayer_sp:1.1.1:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.1.2cpe:2.3:a:realnetworks:realplayer_sp:1.1.2:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.4

Confidence

Low

EPSS

0.836

Percentile

98.5%

Related for CVE-2010-0120