This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Realnetworks First view 2011-11-24
Product Realplayer Last view 2022-06-05
Version 14.0.6 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:realnetworks:realplayer

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
8.8 2022-06-05 CVE-2022-32291

In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.

9.3 2014-07-07 CVE-2014-3113

Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.

9.3 2014-05-20 CVE-2014-3444

The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.

7.5 2014-01-03 CVE-2013-7260

Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877.

9.3 2013-08-26 CVE-2013-4974

RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file.

9.3 2013-08-26 CVE-2013-4973

Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file.

4.3 2013-07-06 CVE-2013-3299

RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string.

9.3 2013-03-20 CVE-2013-1750

Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file.

9.3 2012-12-19 CVE-2012-5691

Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file.

9.3 2012-12-19 CVE-2012-5690

RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer.

7.5 2012-09-12 CVE-2012-3234

RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file.

6.8 2012-09-12 CVE-2012-2410

Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2409.

7.5 2012-09-12 CVE-2012-2409

Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2410.

6.8 2012-09-12 CVE-2012-2408

The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.

7.5 2012-09-12 CVE-2012-2407

Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted AAC file that is not properly handled during stream-data unpacking.

9.3 2012-05-18 CVE-2012-2411

Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file.

9.3 2012-05-18 CVE-2012-2406

RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file.

4.3 2012-03-28 CVE-2012-1904

mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file.

9.3 2012-02-08 CVE-2012-0928

The ATRAC codec in RealNetworks RealPlayer 11.x and 14.x through 14.0.7, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.x before 12.0.0.1703 does not properly decode samples, which allows remote attackers to execute arbitrary code via a crafted ATRAC audio file.

9.3 2012-02-08 CVE-2012-0927

Unspecified vulnerability in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving the coded_frame_size value in a RealAudio audio stream.

9.3 2012-02-08 CVE-2012-0926

The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows remote attackers to execute arbitrary code via a crafted RV10 RealVideo video stream.

9.3 2012-02-08 CVE-2012-0925

Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RV40 RealVideo video stream.

9.3 2012-02-08 CVE-2012-0924

RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving a VIDOBJ_START_CODE code in a header within a video stream.

9.3 2012-02-08 CVE-2012-0923

The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to execute arbitrary code via a crafted RV20 RealVideo video stream.

9.3 2012-02-08 CVE-2012-0922

rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.

CWE : Common Weakness Enumeration

%idName
47% (18) CWE-94 Failure to Control Generation of Code ('Code Injection')
42% (16) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
5% (2) CWE-189 Numeric Errors
5% (2) CWE-20 Improper Input Validation

SAINT Exploits

Description Link
RealPlayer InternetShortcut URL property buffer overflow More info here

Open Source Vulnerability Database (OSVDB)

id Description
77286 RealPlayer RTSP SETUP Request Handling Unspecified Remote Code Execution
77285 RealPlayer RV20 File Decoding Unspecified Remote Code Execution
77284 RealPlayer RV10 Sample Height Handling Unspecified Remote Code Execution
77283 RealPlayer MP4 File Handling Unspecified Remote Code Execution
77282 RealPlayer MP4 Video Dimension Handling Unspecified Remote Memory Corruption
77281 RealPlayer mp4arender.dll module esds Channel Count Handling Remote Overflow
77280 RealPlayer MPG Zero Width Value Handling Remote Memory Corruption
77279 RealPlayer IVR MLTI Chunk Length Handling Remote Overflow
77278 RealPlayer Cook Codec Channel Handling Unspecified Remote Code Execution
77277 RealPlayer RV30 Uninitialized Index Value Handling Unspecified Remote Code Ex...
77276 RealPlayer Invalid Codec Name Handling Unspecified Remote Code Execution
77275 RealPlayer RealAudio Sample Size Handling Unspecified Remote Code Execution
77274 RealPlayer ATRC Codec Handling Unspecified Remote Code Execution
77273 RealPlayer RV30 Encoded File Handling Index Unspecified Remote Code Execution
77272 RealPlayer Channel Change AAC File Handling Remote Overflow
77271 RealPlayer QCELP Stream Handling Unspecified Remote Code Execution
77270 RealPlayer AAC Codec Handling Unspecified Remote Memory Corruption
77269 RealPlayer RealVideo Rendering Handling Unspecified Remote Memory Corruption
77268 RealPlayer RealVideo Rendering Handling Unspecified Remote Overflow

ExploitDB Exploits

id Description
30468 RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - (.rmp) Version Attribute Buffer...

OpenVAS Exploits

id Description
2012-12-25 Name : RealNetworks RealPlayer Code Execution Vulnerabilities - Dec12 (Win)
File : nvt/gb_realplayer_code_exec_vuln_dec12_win.nasl
2012-09-21 Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Mac OS X)
File : nvt/gb_realplayer_mult_vuln_sep12_macosx.nasl
2012-09-21 Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Win)
File : nvt/gb_realplayer_mult_vuln_sep12_win.nasl
2012-04-02 Name : RealNetworks RealPlayer MP4 File Handling Denial of Service Vulnerability (Win)
File : nvt/gb_realplayer_mp4_file_dos_vuln_win.nasl
2012-02-21 Name : RealNetworks RealPlayer Atrac Sample Decoding Remote Code Execution Vulnerab...
File : nvt/gb_realplayer_atrac_sample_code_exec_vuln_macosx.nasl
2012-02-21 Name : RealNetworks RealPlayer Atrac Sample Decoding Remote Code Execution Vulnerab...
File : nvt/gb_realplayer_atrac_sample_code_exec_vuln_win.nasl
2012-02-21 Name : RealNetworks RealPlayer Multiple Vulnerabilities (Win) - Feb12
File : nvt/gb_realplayer_mult_vuln_win_feb12.nasl
2011-11-29 Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Mac OS X)
File : nvt/secpod_realplayer_mult_vuln_nov11_macosx.nasl
2011-11-29 Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Win)
File : nvt/secpod_realplayer_mult_vuln_nov11_win.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2014-A-0097 RealPlayer Memory Corruption Vulnerability
Severity: Category I - VMSKEY: V0052943
2014-A-0013 Multiple Vulnerabilities in RealPlayer
Severity: Category II - VMSKEY: V0043409
2013-A-0166 Multiple Security Vulnerabilities in RealNetworks RealPlayer
Severity: Category II - VMSKEY: V0040163

Snort® IPS/IDS

Date Description
2019-11-12 RealNetworks RealPlayer 3GP file parsing memory corruption attempt
RuleID : 51820 - Type : FILE-MULTIMEDIA - Revision : 1
2019-11-12 RealNetworks RealPlayer 3GP file parsing memory corruption attempt
RuleID : 51819 - Type : FILE-MULTIMEDIA - Revision : 1
2019-04-27 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 49574 - Type : FILE-MULTIMEDIA - Revision : 4
2019-04-27 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 49573 - Type : FILE-MULTIMEDIA - Revision : 4
2014-11-16 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 31376 - Type : FILE-MULTIMEDIA - Revision : 5
2014-01-16 RealNetworks RealPlayer RealMedia URL length buffer overflow attempt
RuleID : 28962 - Type : FILE-MULTIMEDIA - Revision : 10
2014-01-16 RealNetworks RealPlayer RealMedia URL length buffer overflow attempt
RuleID : 28961 - Type : FILE-MULTIMEDIA - Revision : 9
2014-01-10 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 21112 - Type : FILE-MULTIMEDIA - Revision : 15

Nessus® Vulnerability Scanner

id Description
2014-07-10 Name: A multimedia application on the remote Windows host is affected by multiple m...
File: realplayer_17_0_10_8.nasl - Type: ACT_GATHER_INFO
2013-12-31 Name: A multimedia application on the remote Windows host is affected by a buffer o...
File: realplayer_17_0_4_61.nasl - Type: ACT_GATHER_INFO
2013-08-28 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_16_0_3_51.nasl - Type: ACT_GATHER_INFO
2013-03-20 Name: A multimedia application on the remote Windows host is affected by a buffer o...
File: realplayer_16_0_1_18.nasl - Type: ACT_GATHER_INFO
2012-12-18 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_16_0_0_282.nasl - Type: ACT_GATHER_INFO
2012-09-12 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_6_14.nasl - Type: ACT_GATHER_INFO
2012-05-17 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_4_53.nasl - Type: ACT_GATHER_INFO
2012-02-08 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_2_71.nasl - Type: ACT_GATHER_INFO
2011-12-06 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_0_198.nasl - Type: ACT_GATHER_INFO