CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
94.6%
Integer overflow in the pnen3260.dll module in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.1, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via a crafted TIT2 atom in an AAC file.
Vendor | Product | Version | CPE |
---|---|---|---|
realnetworks | realplayer | 11.0 | cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:* |
realnetworks | realplayer | 11.0.1 | cpe:2.3:a:realnetworks:realplayer:11.0.1:*:*:*:*:*:*:* |
realnetworks | realplayer | 11.0.2 | cpe:2.3:a:realnetworks:realplayer:11.0.2:*:*:*:*:*:*:* |
realnetworks | realplayer | 11.0.3 | cpe:2.3:a:realnetworks:realplayer:11.0.3:*:*:*:*:*:*:* |
realnetworks | realplayer | 11.0.4 | cpe:2.3:a:realnetworks:realplayer:11.0.4:*:*:*:*:*:*:* |
realnetworks | realplayer | 11.0.5 | cpe:2.3:a:realnetworks:realplayer:11.0.5:*:*:*:*:*:*:* |
realnetworks | realplayer | 11.1 | cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:* |
realnetworks | realplayer_sp | 1.0.0 | cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:* |
realnetworks | realplayer_sp | 1.0.1 | cpe:2.3:a:realnetworks:realplayer_sp:1.0.1:*:*:*:*:*:*:* |
realnetworks | realplayer_sp | 1.0.2 | cpe:2.3:a:realnetworks:realplayer_sp:1.0.2:*:*:*:*:*:*:* |