Summary
Detail | |||
---|---|---|---|
Vendor | Realnetworks | First view | 2005-06-28 |
Product | Realplayer | Last view | 2022-06-05 |
Version | * | Type | Application |
Update | * | ||
Edition | linux | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:realnetworks:realplayer |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2022-06-05 | CVE-2022-32291 | In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file. |
9.3 | 2014-07-07 | CVE-2014-3113 | Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file. |
9.3 | 2014-05-20 | CVE-2014-3444 | The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file. |
7.5 | 2014-01-03 | CVE-2013-7260 | Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877. |
9.3 | 2013-08-26 | CVE-2013-4974 | RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file. |
9.3 | 2013-08-26 | CVE-2013-4973 | Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file. |
4.3 | 2013-07-06 | CVE-2013-3299 | RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string. |
9.3 | 2013-03-20 | CVE-2013-1750 | Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file. |
9.3 | 2012-12-19 | CVE-2012-5691 | Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file. |
9.3 | 2012-12-19 | CVE-2012-5690 | RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer. |
7.5 | 2012-09-12 | CVE-2012-3234 | RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file. |
6.8 | 2012-09-12 | CVE-2012-2410 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2409. |
7.5 | 2012-09-12 | CVE-2012-2409 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2410. |
6.8 | 2012-09-12 | CVE-2012-2408 | The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding. |
7.5 | 2012-09-12 | CVE-2012-2407 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted AAC file that is not properly handled during stream-data unpacking. |
9.3 | 2012-05-18 | CVE-2012-2411 | Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file. |
9.3 | 2012-05-18 | CVE-2012-2406 | RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file. |
4.3 | 2012-03-28 | CVE-2012-1904 | mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file. |
9.3 | 2011-11-24 | CVE-2011-4262 | Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted MP4 file. |
9.3 | 2011-11-24 | CVE-2011-4261 | RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted video dimensions in an MP4 file. |
9.3 | 2011-11-24 | CVE-2011-4260 | RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed header in an MP4 file. |
9.3 | 2011-11-24 | CVE-2011-4259 | Integer underflow in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted width value in an MPG file. |
9.3 | 2011-11-24 | CVE-2011-4258 | RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file. |
9.3 | 2011-11-24 | CVE-2011-4257 | The Cook codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via crafted channel data. |
10 | 2011-11-24 | CVE-2011-4256 | The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
54% (18) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
33% (11) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
6% (2) | CWE-189 | Numeric Errors |
6% (2) | CWE-20 | Improper Input Validation |
SAINT Exploits
Description | Link |
---|---|
RealPlayer InternetShortcut URL property buffer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
77286 | RealPlayer RTSP SETUP Request Handling Unspecified Remote Code Execution |
77285 | RealPlayer RV20 File Decoding Unspecified Remote Code Execution |
77284 | RealPlayer RV10 Sample Height Handling Unspecified Remote Code Execution |
77283 | RealPlayer MP4 File Handling Unspecified Remote Code Execution |
77282 | RealPlayer MP4 Video Dimension Handling Unspecified Remote Memory Corruption |
77281 | RealPlayer mp4arender.dll module esds Channel Count Handling Remote Overflow |
77280 | RealPlayer MPG Zero Width Value Handling Remote Memory Corruption |
77279 | RealPlayer IVR MLTI Chunk Length Handling Remote Overflow |
77278 | RealPlayer Cook Codec Channel Handling Unspecified Remote Code Execution |
77277 | RealPlayer RV30 Uninitialized Index Value Handling Unspecified Remote Code Ex... |
77276 | RealPlayer Invalid Codec Name Handling Unspecified Remote Code Execution |
77275 | RealPlayer RealAudio Sample Size Handling Unspecified Remote Code Execution |
77274 | RealPlayer ATRC Codec Handling Unspecified Remote Code Execution |
77273 | RealPlayer RV30 Encoded File Handling Index Unspecified Remote Code Execution |
77272 | RealPlayer Channel Change AAC File Handling Remote Overflow |
77271 | RealPlayer QCELP Stream Handling Unspecified Remote Code Execution |
77270 | RealPlayer AAC Codec Handling Unspecified Remote Memory Corruption |
77269 | RealPlayer RealVideo Rendering Handling Unspecified Remote Memory Corruption |
77268 | RealPlayer RealVideo Rendering Handling Unspecified Remote Overflow |
71260 | RealPlayer rvrender.dll IVR File Handling Overflow |
62470 | RealNetworks Multiple Products player/hxclientkit/src/CHXClientSink.cpp Unesc... |
62469 | RealNetworks Multiple Products xcommon/util/hxurl.cpp Unescape Function Overflow |
41730 | RealPlayer RA File Handling Memory Consumption DoS |
17575 | RealPlayer rtffplin.cpp RealText File Parser Overflow |
ExploitDB Exploits
id | Description |
---|---|
30468 | RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - (.rmp) Version Attribute Buffer... |
OpenVAS Exploits
id | Description |
---|---|
2012-12-25 | Name : RealNetworks RealPlayer Code Execution Vulnerabilities - Dec12 (Win) File : nvt/gb_realplayer_code_exec_vuln_dec12_win.nasl |
2012-09-21 | Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Mac OS X) File : nvt/gb_realplayer_mult_vuln_sep12_macosx.nasl |
2012-09-21 | Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Win) File : nvt/gb_realplayer_mult_vuln_sep12_win.nasl |
2012-04-02 | Name : RealNetworks RealPlayer MP4 File Handling Denial of Service Vulnerability (Win) File : nvt/gb_realplayer_mp4_file_dos_vuln_win.nasl |
2011-11-29 | Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Mac OS X) File : nvt/secpod_realplayer_mult_vuln_nov11_macosx.nasl |
2011-11-29 | Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Win) File : nvt/secpod_realplayer_mult_vuln_nov11_win.nasl |
2011-04-11 | Name : RealNetworks RealPlayer IVR File Processing Buffer Overflow Vulnerability (Wi... File : nvt/gb_realplayer_ivr_bof_vuln_win.nasl |
2010-02-15 | Name : CentOS Update for HelixPlayer CESA-2010:0094 centos4 i386 File : nvt/gb_CESA-2010_0094_HelixPlayer_centos4_i386.nasl |
2010-02-15 | Name : RedHat Update for HelixPlayer RHSA-2010:0094-02 File : nvt/gb_RHSA-2010_0094-02_HelixPlayer.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200507-04 (realplayer) File : nvt/glsa_200507_04.nasl |
2008-09-04 | Name : FreeBSD Ports: linux-realplayer File : nvt/freebsd_linux-realplayer1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 826-1 (helix-player) File : nvt/deb_826_1.nasl |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2014-A-0097 | RealPlayer Memory Corruption Vulnerability Severity: Category I - VMSKEY: V0052943 |
2014-A-0013 | Multiple Vulnerabilities in RealPlayer Severity: Category II - VMSKEY: V0043409 |
2013-A-0166 | Multiple Security Vulnerabilities in RealNetworks RealPlayer Severity: Category II - VMSKEY: V0040163 |
2010-A-0022 | Multiple HelixPlayer Vulnerabilities in Red Hat Enterprise Linux 4 Severity: Category II - VMSKEY: V0022670 |
Snort® IPS/IDS
Date | Description |
---|---|
2019-11-12 | RealNetworks RealPlayer 3GP file parsing memory corruption attempt RuleID : 51820 - Type : FILE-MULTIMEDIA - Revision : 1 |
2019-11-12 | RealNetworks RealPlayer 3GP file parsing memory corruption attempt RuleID : 51819 - Type : FILE-MULTIMEDIA - Revision : 1 |
2019-04-27 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 49574 - Type : FILE-MULTIMEDIA - Revision : 4 |
2019-04-27 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 49573 - Type : FILE-MULTIMEDIA - Revision : 4 |
2014-01-10 | RealNetworks RealPlayer realtext file bad version buffer overflow attempt RuleID : 3823 - Type : FILE-MULTIMEDIA - Revision : 21 |
2014-01-10 | RealNetworks RealPlayer realtext long URI request attempt RuleID : 3822 - Type : SERVER-WEBAPP - Revision : 15 |
2014-11-16 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 31376 - Type : FILE-MULTIMEDIA - Revision : 5 |
2014-01-16 | RealNetworks RealPlayer RealMedia URL length buffer overflow attempt RuleID : 28962 - Type : FILE-MULTIMEDIA - Revision : 10 |
2014-01-16 | RealNetworks RealPlayer RealMedia URL length buffer overflow attempt RuleID : 28961 - Type : FILE-MULTIMEDIA - Revision : 9 |
2014-01-10 | RealNetworks RealPlayer mpeg width integer memory underflow attempt RuleID : 21112 - Type : FILE-MULTIMEDIA - Revision : 15 |
2014-01-10 | RealNetworks RealPlayer IVR handling heap buffer overflow attempt RuleID : 19127 - Type : FILE-MULTIMEDIA - Revision : 15 |
2014-01-10 | RealNetworks RealPlayer IVR handling heap buffer overflow attempt RuleID : 19126 - Type : FILE-MULTIMEDIA - Revision : 15 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2014-07-10 | Name: A multimedia application on the remote Windows host is affected by multiple m... File: realplayer_17_0_10_8.nasl - Type: ACT_GATHER_INFO |
2013-12-31 | Name: A multimedia application on the remote Windows host is affected by a buffer o... File: realplayer_17_0_4_61.nasl - Type: ACT_GATHER_INFO |
2013-08-28 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_16_0_3_51.nasl - Type: ACT_GATHER_INFO |
2013-07-12 | Name: The remote Oracle Linux host is missing a security update. File: oraclelinux_ELSA-2010-0094.nasl - Type: ACT_GATHER_INFO |
2013-03-20 | Name: A multimedia application on the remote Windows host is affected by a buffer o... File: realplayer_16_0_1_18.nasl - Type: ACT_GATHER_INFO |
2012-12-18 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_16_0_0_282.nasl - Type: ACT_GATHER_INFO |
2012-09-12 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_6_14.nasl - Type: ACT_GATHER_INFO |
2012-08-01 | Name: The remote Scientific Linux host is missing a security update. File: sl_20100209_HelixPlayer_on_SL4_x.nasl - Type: ACT_GATHER_INFO |
2012-05-17 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_4_53.nasl - Type: ACT_GATHER_INFO |
2011-12-06 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_15_0_0_198.nasl - Type: ACT_GATHER_INFO |
2011-04-14 | Name: A multimedia application on the remote Windows host is affected by multiple v... File: realplayer_12_0_1_647.nasl - Type: ACT_GATHER_INFO |
2010-02-10 | Name: The remote Red Hat host is missing a security update. File: redhat-RHSA-2010-0094.nasl - Type: ACT_GATHER_INFO |
2010-02-10 | Name: The remote CentOS host is missing a security update. File: centos_RHSA-2010-0094.nasl - Type: ACT_GATHER_INFO |
2006-07-05 | Name: The remote CentOS host is missing a security update. File: centos_RHSA-2005-517.nasl - Type: ACT_GATHER_INFO |
2005-10-05 | Name: The remote Debian host is missing a security-related update. File: debian_DSA-826.nasl - Type: ACT_GATHER_INFO |
2005-07-20 | Name: The remote host is missing a vendor-supplied security patch File: suse_SA_2005_037.nasl - Type: ACT_GATHER_INFO |
2005-07-13 | Name: The remote FreeBSD host is missing a security-related update. File: freebsd_pkg_95ee96f2e48811d9bf22080020c11455.nasl - Type: ACT_GATHER_INFO |
2005-07-06 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-200507-04.nasl - Type: ACT_GATHER_INFO |
2005-06-24 | Name: The remote Windows application is affected by multiple vulnerabilities. File: realplayer_realtext_parsing_overflow.nasl - Type: ACT_GATHER_INFO |
2005-06-24 | Name: The remote Red Hat host is missing a security update. File: redhat-RHSA-2005-517.nasl - Type: ACT_GATHER_INFO |
2005-06-24 | Name: The remote Red Hat host is missing one or more security updates. File: redhat-RHSA-2005-523.nasl - Type: ACT_GATHER_INFO |