Summary
Detail | |||
---|---|---|---|
Vendor | Realnetworks | First view | 2011-11-24 |
Product | Realplayer | Last view | 2022-06-05 |
Version | 14.0.6 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:realnetworks:realplayer |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2022-06-05 | CVE-2022-32291 | In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file. |
9.3 | 2014-07-07 | CVE-2014-3113 | Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file. |
9.3 | 2014-05-20 | CVE-2014-3444 | The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file. |
7.5 | 2014-01-03 | CVE-2013-7260 | Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877. |
9.3 | 2013-08-26 | CVE-2013-4974 | RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file. |
9.3 | 2013-08-26 | CVE-2013-4973 | Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file. |
4.3 | 2013-07-06 | CVE-2013-3299 | RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string. |
9.3 | 2013-03-20 | CVE-2013-1750 | Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file. |
9.3 | 2012-12-19 | CVE-2012-5691 | Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file. |
9.3 | 2012-12-19 | CVE-2012-5690 | RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer. |
7.5 | 2012-09-12 | CVE-2012-3234 | RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file. |
6.8 | 2012-09-12 | CVE-2012-2410 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2409. |
7.5 | 2012-09-12 | CVE-2012-2409 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2410. |
6.8 | 2012-09-12 | CVE-2012-2408 | The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding. |
7.5 | 2012-09-12 | CVE-2012-2407 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted AAC file that is not properly handled during stream-data unpacking. |
9.3 | 2012-05-18 | CVE-2012-2411 | Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file. |
9.3 | 2012-05-18 | CVE-2012-2406 | RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file. |
4.3 | 2012-03-28 | CVE-2012-1904 | mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file. |
9.3 | 2012-02-08 | CVE-2012-0928 | The ATRAC codec in RealNetworks RealPlayer 11.x and 14.x through 14.0.7, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer 12.x before 12.0.0.1703 does not properly decode samples, which allows remote attackers to execute arbitrary code via a crafted ATRAC audio file. |
9.3 | 2012-02-08 | CVE-2012-0927 | Unspecified vulnerability in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving the coded_frame_size value in a RealAudio audio stream. |
9.3 | 2012-02-08 | CVE-2012-0926 | The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows remote attackers to execute arbitrary code via a crafted RV10 RealVideo video stream. |
9.3 | 2012-02-08 | CVE-2012-0925 | Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RV40 RealVideo video stream. |
9.3 | 2012-02-08 | CVE-2012-0924 | RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving a VIDOBJ_START_CODE code in a header within a video stream. |
9.3 | 2012-02-08 | CVE-2012-0923 | The RV20 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle the frame size array, which allows remote attackers to execute arbitrary code via a crafted RV20 RealVideo video stream. |
9.3 | 2012-02-08 | CVE-2012-0922 | rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
47% (18) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
42% (16) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
5% (2) | CWE-189 | Numeric Errors |
5% (2) | CWE-20 | Improper Input Validation |
SAINT Exploits
Description | Link |
---|---|
RealPlayer InternetShortcut URL property buffer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
77286 | RealPlayer RTSP SETUP Request Handling Unspecified Remote Code Execution |
77285 | RealPlayer RV20 File Decoding Unspecified Remote Code Execution |
77284 | RealPlayer RV10 Sample Height Handling Unspecified Remote Code Execution |
77283 | RealPlayer MP4 File Handling Unspecified Remote Code Execution |
77282 | RealPlayer MP4 Video Dimension Handling Unspecified Remote Memory Corruption |
77281 | RealPlayer mp4arender.dll module esds Channel Count Handling Remote Overflow |
77280 | RealPlayer MPG Zero Width Value Handling Remote Memory Corruption |
77279 | RealPlayer IVR MLTI Chunk Length Handling Remote Overflow |
77278 | RealPlayer Cook Codec Channel Handling Unspecified Remote Code Execution |
77277 | RealPlayer RV30 Uninitialized Index Value Handling Unspecified Remote Code Ex... |
77276 | RealPlayer Invalid Codec Name Handling Unspecified Remote Code Execution |
77275 | RealPlayer RealAudio Sample Size Handling Unspecified Remote Code Execution |
77274 | RealPlayer ATRC Codec Handling Unspecified Remote Code Execution |
77273 | RealPlayer RV30 Encoded File Handling Index Unspecified Remote Code Execution |
77272 | RealPlayer Channel Change AAC File Handling Remote Overflow |
77271 | RealPlayer QCELP Stream Handling Unspecified Remote Code Execution |
77270 | RealPlayer AAC Codec Handling Unspecified Remote Memory Corruption |
77269 | RealPlayer RealVideo Rendering Handling Unspecified Remote Memory Corruption |
77268 | RealPlayer RealVideo Rendering Handling Unspecified Remote Overflow |
ExploitDB Exploits
id | Description |
---|---|
30468 | RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - (.rmp) Version Attribute Buffer... |
OpenVAS Exploits
id | Description |
---|---|
2012-12-25 | Name : RealNetworks RealPlayer Code Execution Vulnerabilities - Dec12 (Win) File : nvt/gb_realplayer_code_exec_vuln_dec12_win.nasl |
2012-09-21 | Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Mac OS X) File : nvt/gb_realplayer_mult_vuln_sep12_macosx.nasl |
2012-09-21 | Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Win) File : nvt/gb_realplayer_mult_vuln_sep12_win.nasl |
2012-04-02 | Name : RealNetworks RealPlayer MP4 File Handling Denial of Service Vulnerability (Win) File : nvt/gb_realplayer_mp4_file_dos_vuln_win.nasl |
2012-02-21 | Name : RealNetworks RealPlayer Atrac Sample Decoding Remote Code Execution Vulnerab... File : nvt/gb_realplayer_atrac_sample_code_exec_vuln_macosx.nasl |
2012-02-21 | Name : RealNetworks RealPlayer Atrac Sample Decoding Remote Code Execution Vulnerab... File : nvt/gb_realplayer_atrac_sample_code_exec_vuln_win.nasl |
2012-02-21 | Name : RealNetworks RealPlayer Multiple Vulnerabilities (Win) - Feb12 File : nvt/gb_realplayer_mult_vuln_win_feb12.nasl |
2011-11-29 | Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Mac OS X) File : nvt/secpod_realplayer_mult_vuln_nov11_macosx.nasl |
2011-11-29 | Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Win) File : nvt/secpod_realplayer_mult_vuln_nov11_win.nasl |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2014-A-0097 | RealPlayer Memory Corruption Vulnerability Severity: Category I - VMSKEY: V0052943 |
2014-A-0013 | Multiple Vulnerabilities in RealPlayer Severity: Category II - VMSKEY: V0043409 |
2013-A-0166 | Multiple Security Vulnerabilities in RealNetworks RealPlayer Severity: Category II - VMSKEY: V0040163 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-11-12 | RealNetworks RealPlayer 3GP file parsing memory corruption attempt RuleID : 51820 - Type : FILE-MULTIMEDIA - Revision : 1 |
2019-11-12 | RealNetworks RealPlayer 3GP file parsing memory corruption attempt RuleID : 51819 - Type : FILE-MULTIMEDIA - Revision : 1 |
2019-04-27 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 49574 - Type : FILE-MULTIMEDIA - Revision : 4 |
2019-04-27 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 49573 - Type : FILE-MULTIMEDIA - Revision : 4 |
2014-11-16 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 31376 - Type : FILE-MULTIMEDIA - Revision : 5 |
2014-01-16 | RealNetworks RealPlayer RealMedia URL length buffer overflow attempt RuleID : 28962 - Type : FILE-MULTIMEDIA - Revision : 10 |
2014-01-16 | RealNetworks RealPlayer RealMedia URL length buffer overflow attempt RuleID : 28961 - Type : FILE-MULTIMEDIA - Revision : 9 |
2014-01-10 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 21112 - Type : FILE-MULTIMEDIA - Revision : 15 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2014-07-10 | Name: A multimedia application on the remote Windows host is affected by multiple m... File: realplayer_17_0_10_8.nasl - Type: ACT_GATHER_INFO |
2013-12-31 | Name: A multimedia application on the remote Windows host is affected by a buffer o... File: realplayer_17_0_4_61.nasl - Type: ACT_GATHER_INFO |
2013-08-28 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_16_0_3_51.nasl - Type: ACT_GATHER_INFO |
2013-03-20 | Name: A multimedia application on the remote Windows host is affected by a buffer o... File: realplayer_16_0_1_18.nasl - Type: ACT_GATHER_INFO |
2012-12-18 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_16_0_0_282.nasl - Type: ACT_GATHER_INFO |
2012-09-12 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_6_14.nasl - Type: ACT_GATHER_INFO |
2012-05-17 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_4_53.nasl - Type: ACT_GATHER_INFO |
2012-02-08 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_2_71.nasl - Type: ACT_GATHER_INFO |
2011-12-06 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_0_198.nasl - Type: ACT_GATHER_INFO |