Lucene search

K
nvd[email protected]NVD:CVE-2005-2922
HistoryDec 31, 2005 - 5:00 a.m.

CVE-2005-2922

2005-12-3105:00:00
CWE-119
web.nvd.nist.gov
6

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.024

Percentile

89.9%

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

Affected configurations

Nvd
Node
realnetworkshelix_playerMatch10.0linux
OR
realnetworkshelix_playerMatch10.0.1linux
OR
realnetworkshelix_playerMatch10.0.2linux
OR
realnetworkshelix_playerMatch10.0.3linux
OR
realnetworkshelix_playerMatch10.0.4linux
OR
realnetworkshelix_playerMatch10.0.5linux
OR
realnetworkshelix_playerMatch10.0.6linux
OR
realnetworksrealone_player
OR
realnetworksrealone_playerMatch0.288mac_os_x
OR
realnetworksrealone_playerMatch0.297mac_os_x
OR
realnetworksrealone_playerMatch1.0
OR
realnetworksrealone_playerMatch2.0
OR
realnetworksrealplayerenterprise
OR
realnetworksrealplayerMatch8.0win32
OR
realnetworksrealplayerMatch10.0
OR
realnetworksrealplayerMatch10.0.0.305mac_os
OR
realnetworksrealplayerMatch10.0.0.331mac_os
OR
realnetworksrealplayerMatch10.0.1linux
OR
realnetworksrealplayerMatch10.0.2linux
OR
realnetworksrealplayerMatch10.0.3linux
OR
realnetworksrealplayerMatch10.0.4linux
OR
realnetworksrealplayerMatch10.0.5linux
OR
realnetworksrealplayerMatch10.0.6linux
OR
realnetworksrealplayerMatch10.5
OR
realnetworksrealplayerMatch10.5_6.0.12.1040
OR
realnetworksrealplayerMatch10.5_6.0.12.1053
OR
realnetworksrealplayerMatch10.5_6.0.12.1056
OR
realnetworksrealplayerMatch10.5_6.0.12.1059
OR
realnetworksrealplayerMatch10.5_6.0.12.1069
OR
realnetworksrealplayerMatch10.5_6.0.12.1235
OR
realnetworksrhapsodyMatch3.0
OR
realnetworksrhapsodyMatch3.0_build_0.815
VendorProductVersionCPE
realnetworkshelix_player10.0cpe:2.3:a:realnetworks:helix_player:10.0:*:linux:*:*:*:*:*
realnetworkshelix_player10.0.1cpe:2.3:a:realnetworks:helix_player:10.0.1:*:linux:*:*:*:*:*
realnetworkshelix_player10.0.2cpe:2.3:a:realnetworks:helix_player:10.0.2:*:linux:*:*:*:*:*
realnetworkshelix_player10.0.3cpe:2.3:a:realnetworks:helix_player:10.0.3:*:linux:*:*:*:*:*
realnetworkshelix_player10.0.4cpe:2.3:a:realnetworks:helix_player:10.0.4:*:linux:*:*:*:*:*
realnetworkshelix_player10.0.5cpe:2.3:a:realnetworks:helix_player:10.0.5:*:linux:*:*:*:*:*
realnetworkshelix_player10.0.6cpe:2.3:a:realnetworks:helix_player:10.0.6:*:linux:*:*:*:*:*
realnetworksrealone_player*cpe:2.3:a:realnetworks:realone_player:*:*:*:*:*:*:*:*
realnetworksrealone_player0.288cpe:2.3:a:realnetworks:realone_player:0.288:*:mac_os_x:*:*:*:*:*
realnetworksrealone_player0.297cpe:2.3:a:realnetworks:realone_player:0.297:*:mac_os_x:*:*:*:*:*
Rows per page:
1-10 of 321

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.024

Percentile

89.9%