Lucene search

K
cveMitreCVE-2010-4393
HistoryJan 31, 2011 - 9:00 p.m.

CVE-2010-4393

2011-01-3121:00:03
CWE-119
mitre
web.nvd.nist.gov
37
cve-2010-4393
buffer overflow
realplayer
remote code execution
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.845

Percentile

98.6%

Heap-based buffer overflow in vidplin.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.x before 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted header in an AVI file.

Affected configurations

Nvd
Node
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.1
Node
realnetworksrealplayerMatch14.0.0
OR
realnetworksrealplayerMatch14.0.1
Node
realnetworksrealplayer_spMatch1.0.0
OR
realnetworksrealplayer_spMatch1.0.1
OR
realnetworksrealplayer_spMatch1.0.2
OR
realnetworksrealplayer_spMatch1.0.5
OR
realnetworksrealplayer_spMatch1.1
OR
realnetworksrealplayer_spMatch1.1.1
OR
realnetworksrealplayer_spMatch1.1.2
OR
realnetworksrealplayer_spMatch1.1.3
OR
realnetworksrealplayer_spMatch1.1.4
OR
realnetworksrealplayer_spMatch1.1.5
VendorProductVersionCPE
realnetworksrealplayer11.0cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*
realnetworksrealplayer11.1cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:*
realnetworksrealplayer14.0.0cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:*
realnetworksrealplayer14.0.1cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.0cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.1cpe:2.3:a:realnetworks:realplayer_sp:1.0.1:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.2cpe:2.3:a:realnetworks:realplayer_sp:1.0.2:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.5cpe:2.3:a:realnetworks:realplayer_sp:1.0.5:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.1cpe:2.3:a:realnetworks:realplayer_sp:1.1:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.1.1cpe:2.3:a:realnetworks:realplayer_sp:1.1.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.845

Percentile

98.6%