Search Results (Refine Search)
- CPE Product Version: cpe:/a:realnetworks:realplayer:11.0.2
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2011-4247 |
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted QCELP stream. Published: November 24, 2011; 6:55:07 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2011-4246 |
The AAC codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Published: November 24, 2011; 6:55:07 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
CVE-2011-4245 |
The RealVideo renderer in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. Published: November 24, 2011; 6:55:06 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
CVE-2011-4244 |
Heap-based buffer overflow in the RealVideo renderer in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors. Published: November 24, 2011; 6:55:06 AM -0500 |
V3.x:(not available) V2.0: 10.0 HIGH |
CVE-2011-1525 |
Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted frame in an Internet Video Recording (IVR) file. Published: April 06, 2011; 12:55:15 PM -0400 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4397 |
Integer overflow in the pnen3260.dll module in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.1, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via a crafted TIT2 atom in an AAC file. Published: December 14, 2010; 11:00:05 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4396 |
Cross-zone scripting vulnerability in the HandleAction method in a certain ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 allows remote attackers to inject arbitrary web script or HTML in the Local Zone by specifying a local file in a NavigateToURL action, as demonstrated by a local skin file. Published: December 14, 2010; 11:00:05 AM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2010-4395 |
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via a crafted conditional component in AAC frame data. Published: December 14, 2010; 11:00:05 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4394 |
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.5 allows remote web servers to execute arbitrary code via a long Server header in a response to an HTTP request that occurs during parsing of a RealPix file. Published: December 14, 2010; 11:00:05 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4392 |
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, RealPlayer Enterprise 2.1.2 and 2.1.3, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to execute arbitrary code via crafted ImageMap data in a RealMedia file, related to certain improper integer calculations. Published: December 14, 2010; 11:00:05 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4391 |
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allows remote attackers to execute arbitrary code via a crafted value in an unspecified header field in an RMX file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4390 |
Multiple heap-based buffer overflows in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allow remote attackers to have an unspecified impact via a crafted header in an IVR file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4389 |
Heap-based buffer overflow in the cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via unspecified data in the initialization buffer. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4388 |
The (1) Upsell.htm, (2) Main.html, and (3) Custsupport.html components in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allow remote attackers to inject code into the RealOneActiveXObject process, and consequently bypass intended Local Machine Zone restrictions and load arbitrary ActiveX controls, via unspecified vectors. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2010-4387 |
The RealAudio codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, Mac RealPlayer 11.0 through 12.0.0.1444, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted audio stream in a RealMedia file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4386 |
RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted RealMedia video file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4385 |
Integer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to have an unspecified impact via crafted frame dimensions in an SIPR stream. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4384 |
Array index error in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 11.1, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to execute arbitrary code via a malformed Media Properties Header (aka MDPR) in a RealMedia file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4383 |
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 12.0.0.1444, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to have an unspecified impact via a crafted RA5 file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |
CVE-2010-4382 |
Multiple heap-based buffer overflows in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allow remote attackers to have an unspecified impact via a crafted RealMedia file. Published: December 14, 2010; 11:00:04 AM -0500 |
V3.x:(not available) V2.0: 9.3 HIGH |