Lucene search

K
cveMitreCVE-2012-2408
HistorySep 12, 2012 - 10:38 a.m.

CVE-2012-2408

2012-09-1210:38:33
CWE-119
mitre
web.nvd.nist.gov
35
aac sdk
realnetworks
realplayer
cve-2012-2408
remote attack
denial of service
heap memory corruption

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

58.4%

The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.

Affected configurations

Nvd
Node
realnetworksrealplayerRange15.0.5.109
OR
realnetworksrealplayerMatch2.1.2enterprise
OR
realnetworksrealplayerMatch2.1.3enterprise
OR
realnetworksrealplayerMatch2.1.4enterprise
OR
realnetworksrealplayerMatch4
OR
realnetworksrealplayerMatch5
OR
realnetworksrealplayerMatch6
OR
realnetworksrealplayerMatch7
OR
realnetworksrealplayerMatch8
OR
realnetworksrealplayerMatch10.0
OR
realnetworksrealplayerMatch10.5
OR
realnetworksrealplayerMatch11.0
OR
realnetworksrealplayerMatch11.0.1
OR
realnetworksrealplayerMatch11.0.2
OR
realnetworksrealplayerMatch11.0.2.1744
OR
realnetworksrealplayerMatch11.0.2.2315
OR
realnetworksrealplayerMatch11.0.3
OR
realnetworksrealplayerMatch11.0.4
OR
realnetworksrealplayerMatch11.0.5
OR
realnetworksrealplayerMatch11.1
OR
realnetworksrealplayerMatch11.1.3
OR
realnetworksrealplayerMatch11_build_6.0.14.748
OR
realnetworksrealplayerMatch12.0.0.1444
OR
realnetworksrealplayerMatch12.0.0.1548
OR
realnetworksrealplayerMatch14.0.0
OR
realnetworksrealplayerMatch14.0.1
OR
realnetworksrealplayerMatch14.0.1.609
OR
realnetworksrealplayerMatch14.0.2
OR
realnetworksrealplayerMatch14.0.3
OR
realnetworksrealplayerMatch14.0.4
OR
realnetworksrealplayerMatch14.0.5
OR
realnetworksrealplayerMatch15.0.2.72
OR
realnetworksrealplayerMatch15.0.3.37
Node
realnetworksrealplayer_spMatch1.0.0
OR
realnetworksrealplayer_spMatch1.0.1
OR
realnetworksrealplayer_spMatch1.0.2
OR
realnetworksrealplayer_spMatch1.0.5
OR
realnetworksrealplayer_spMatch1.1
OR
realnetworksrealplayer_spMatch1.1.1
OR
realnetworksrealplayer_spMatch1.1.2
OR
realnetworksrealplayer_spMatch1.1.3
OR
realnetworksrealplayer_spMatch1.1.4
OR
realnetworksrealplayer_spMatch1.1.5
Node
realnetworksrealplayerMatch12.0.0.1701mac
VendorProductVersionCPE
realnetworksrealplayer*cpe:2.3:a:realnetworks:realplayer:*:*:*:*:*:*:*:*
realnetworksrealplayer2.1.2cpe:2.3:a:realnetworks:realplayer:2.1.2:*:enterprise:*:*:*:*:*
realnetworksrealplayer2.1.3cpe:2.3:a:realnetworks:realplayer:2.1.3:*:enterprise:*:*:*:*:*
realnetworksrealplayer2.1.4cpe:2.3:a:realnetworks:realplayer:2.1.4:*:enterprise:*:*:*:*:*
realnetworksrealplayer4cpe:2.3:a:realnetworks:realplayer:4:*:*:*:*:*:*:*
realnetworksrealplayer5cpe:2.3:a:realnetworks:realplayer:5:*:*:*:*:*:*:*
realnetworksrealplayer6cpe:2.3:a:realnetworks:realplayer:6:*:*:*:*:*:*:*
realnetworksrealplayer7cpe:2.3:a:realnetworks:realplayer:7:*:*:*:*:*:*:*
realnetworksrealplayer8cpe:2.3:a:realnetworks:realplayer:8:*:*:*:*:*:*:*
realnetworksrealplayer10.0cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 441

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

58.4%

Related for CVE-2012-2408