Lucene search

K
cveMitreCVE-2013-6877
HistoryDec 19, 2013 - 10:55 p.m.

CVE-2013-6877

2013-12-1922:55:04
CWE-119
mitre
web.nvd.nist.gov
37
cve
realnetworks
realplayer
buffer overflow
remote code execution
trackid
rmp file
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.966

Percentile

99.7%

Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a long string in the TRACKID element of an RMP file, a different vulnerability than CVE-2013-7260.

Affected configurations

Nvd
Node
realnetworksrealplayerMatch16.0.2.32
OR
realnetworksrealplayerMatch16.0.3.51
VendorProductVersionCPE
realnetworksrealplayer16.0.2.32cpe:2.3:a:realnetworks:realplayer:16.0.2.32:*:*:*:*:*:*:*
realnetworksrealplayer16.0.3.51cpe:2.3:a:realnetworks:realplayer:16.0.3.51:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.966

Percentile

99.7%