Lucene search

K
cveMitreCVE-2011-1221
HistoryOct 04, 2011 - 10:55 p.m.

CVE-2011-1221

2011-10-0422:55:01
CWE-79
mitre
web.nvd.nist.gov
32
cve-2011-1221
cross-zone scripting
realplayer
activex control
realnetworks
remote attackers
web script
html
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.009

Percentile

83.2%

Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document, a different vulnerability than CVE-2011-2947.

Affected configurations

Nvd
Node
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.1
Node
realnetworksrealplayerMatch14.0.0
OR
realnetworksrealplayerMatch14.0.1
OR
realnetworksrealplayerMatch14.0.2
OR
realnetworksrealplayerMatch14.0.3
OR
realnetworksrealplayerMatch14.0.4
OR
realnetworksrealplayerMatch14.0.5
Node
realnetworksrealplayer_spMatch1.0.0
OR
realnetworksrealplayer_spMatch1.0.1
OR
realnetworksrealplayer_spMatch1.0.2
OR
realnetworksrealplayer_spMatch1.0.5
OR
realnetworksrealplayer_spMatch1.1
OR
realnetworksrealplayer_spMatch1.1.1
OR
realnetworksrealplayer_spMatch1.1.2
OR
realnetworksrealplayer_spMatch1.1.3
OR
realnetworksrealplayer_spMatch1.1.4
OR
realnetworksrealplayer_spMatch1.1.5
Node
realnetworksrealplayerMatch2.0enterprise
OR
realnetworksrealplayerMatch2.1enterprise
OR
realnetworksrealplayerMatch2.1.2enterprise
OR
realnetworksrealplayerMatch2.1.3enterprise
OR
realnetworksrealplayerMatch2.1.4enterprise
OR
realnetworksrealplayerMatch2.1.5enterprise
VendorProductVersionCPE
realnetworksrealplayer11.0cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*
realnetworksrealplayer11.1cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:*
realnetworksrealplayer14.0.0cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:*
realnetworksrealplayer14.0.1cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:*
realnetworksrealplayer14.0.2cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:*
realnetworksrealplayer14.0.3cpe:2.3:a:realnetworks:realplayer:14.0.3:*:*:*:*:*:*:*
realnetworksrealplayer14.0.4cpe:2.3:a:realnetworks:realplayer:14.0.4:*:*:*:*:*:*:*
realnetworksrealplayer14.0.5cpe:2.3:a:realnetworks:realplayer:14.0.5:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.0cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:*
realnetworksrealplayer_sp1.0.1cpe:2.3:a:realnetworks:realplayer_sp:1.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.009

Percentile

83.2%