This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Realnetworks First view 2005-06-28
Product Realplayer Last view 2022-06-05
Version 10.0 Type Application
Update *  
Edition *  
Language japanese  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:realnetworks:realplayer

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
8.8 2022-06-05 CVE-2022-32291

In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.

9.3 2014-07-07 CVE-2014-3113

Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.

9.3 2014-05-20 CVE-2014-3444

The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.

7.5 2014-01-03 CVE-2013-7260

Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877.

9.3 2013-08-26 CVE-2013-4974

RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file.

9.3 2013-08-26 CVE-2013-4973

Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file.

4.3 2013-07-06 CVE-2013-3299

RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string.

9.3 2013-03-20 CVE-2013-1750

Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file.

9.3 2012-12-19 CVE-2012-5691

Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file.

9.3 2012-12-19 CVE-2012-5690

RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that triggers access to an invalid pointer.

7.5 2012-09-12 CVE-2012-3234

RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in RealAudio files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) or possibly have unspecified other impact via a crafted file.

6.8 2012-09-12 CVE-2012-2410

Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2409.

7.5 2012-09-12 CVE-2012-2409

Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted RealMedia file, a different vulnerability than CVE-2012-2410.

6.8 2012-09-12 CVE-2012-2408

The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted AAC file that is not properly handled during decoding.

7.5 2012-09-12 CVE-2012-2407

Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted AAC file that is not properly handled during stream-data unpacking.

9.3 2012-05-18 CVE-2012-2411

Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RealJukebox Media file.

9.3 2012-05-18 CVE-2012-2406

RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote attackers to execute arbitrary code via a crafted file.

4.3 2012-03-28 CVE-2012-1904

mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP4 file.

9.3 2011-11-24 CVE-2011-4262

Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted MP4 file.

9.3 2011-11-24 CVE-2011-4261

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted video dimensions in an MP4 file.

9.3 2011-11-24 CVE-2011-4260

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed header in an MP4 file.

9.3 2011-11-24 CVE-2011-4259

Integer underflow in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted width value in an MPG file.

9.3 2011-11-24 CVE-2011-4258

RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file.

9.3 2011-11-24 CVE-2011-4257

The Cook codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via crafted channel data.

10 2011-11-24 CVE-2011-4256

The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors.

CWE : Common Weakness Enumeration

%idName
53% (17) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
34% (11) CWE-94 Failure to Control Generation of Code ('Code Injection')
6% (2) CWE-189 Numeric Errors
6% (2) CWE-20 Improper Input Validation

SAINT Exploits

Description Link
RealPlayer InternetShortcut URL property buffer overflow More info here

Open Source Vulnerability Database (OSVDB)

id Description
77286 RealPlayer RTSP SETUP Request Handling Unspecified Remote Code Execution
77285 RealPlayer RV20 File Decoding Unspecified Remote Code Execution
77284 RealPlayer RV10 Sample Height Handling Unspecified Remote Code Execution
77283 RealPlayer MP4 File Handling Unspecified Remote Code Execution
77282 RealPlayer MP4 Video Dimension Handling Unspecified Remote Memory Corruption
77281 RealPlayer mp4arender.dll module esds Channel Count Handling Remote Overflow
77280 RealPlayer MPG Zero Width Value Handling Remote Memory Corruption
77279 RealPlayer IVR MLTI Chunk Length Handling Remote Overflow
77278 RealPlayer Cook Codec Channel Handling Unspecified Remote Code Execution
77277 RealPlayer RV30 Uninitialized Index Value Handling Unspecified Remote Code Ex...
77276 RealPlayer Invalid Codec Name Handling Unspecified Remote Code Execution
77275 RealPlayer RealAudio Sample Size Handling Unspecified Remote Code Execution
77274 RealPlayer ATRC Codec Handling Unspecified Remote Code Execution
77273 RealPlayer RV30 Encoded File Handling Index Unspecified Remote Code Execution
77272 RealPlayer Channel Change AAC File Handling Remote Overflow
77271 RealPlayer QCELP Stream Handling Unspecified Remote Code Execution
77270 RealPlayer AAC Codec Handling Unspecified Remote Memory Corruption
77269 RealPlayer RealVideo Rendering Handling Unspecified Remote Memory Corruption
77268 RealPlayer RealVideo Rendering Handling Unspecified Remote Overflow
71260 RealPlayer rvrender.dll IVR File Handling Overflow
41730 RealPlayer RA File Handling Memory Consumption DoS
17575 RealPlayer rtffplin.cpp RealText File Parser Overflow

ExploitDB Exploits

id Description
30468 RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - (.rmp) Version Attribute Buffer...

OpenVAS Exploits

id Description
2012-12-25 Name : RealNetworks RealPlayer Code Execution Vulnerabilities - Dec12 (Win)
File : nvt/gb_realplayer_code_exec_vuln_dec12_win.nasl
2012-09-21 Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Mac OS X)
File : nvt/gb_realplayer_mult_vuln_sep12_macosx.nasl
2012-09-21 Name : RealNetworks RealPlayer Multiple Vulnerabilities - Sep12 (Win)
File : nvt/gb_realplayer_mult_vuln_sep12_win.nasl
2012-04-02 Name : RealNetworks RealPlayer MP4 File Handling Denial of Service Vulnerability (Win)
File : nvt/gb_realplayer_mp4_file_dos_vuln_win.nasl
2011-11-29 Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Mac OS X)
File : nvt/secpod_realplayer_mult_vuln_nov11_macosx.nasl
2011-11-29 Name : RealNetworks RealPlayer Multiple Vulnerabilities Nov - 11 (Win)
File : nvt/secpod_realplayer_mult_vuln_nov11_win.nasl
2011-04-11 Name : RealNetworks RealPlayer IVR File Processing Buffer Overflow Vulnerability (Wi...
File : nvt/gb_realplayer_ivr_bof_vuln_win.nasl
2008-09-24 Name : Gentoo Security Advisory GLSA 200507-04 (realplayer)
File : nvt/glsa_200507_04.nasl
2008-09-04 Name : FreeBSD Ports: linux-realplayer
File : nvt/freebsd_linux-realplayer1.nasl
2008-01-17 Name : Debian Security Advisory DSA 826-1 (helix-player)
File : nvt/deb_826_1.nasl

Information Assurance Vulnerability Management (IAVM)

id Description
2014-A-0097 RealPlayer Memory Corruption Vulnerability
Severity: Category I - VMSKEY: V0052943
2014-A-0013 Multiple Vulnerabilities in RealPlayer
Severity: Category II - VMSKEY: V0043409
2013-A-0166 Multiple Security Vulnerabilities in RealNetworks RealPlayer
Severity: Category II - VMSKEY: V0040163

Snort® IPS/IDS

Date Description
2019-11-12 RealNetworks RealPlayer 3GP file parsing memory corruption attempt
RuleID : 51820 - Type : FILE-MULTIMEDIA - Revision : 1
2019-11-12 RealNetworks RealPlayer 3GP file parsing memory corruption attempt
RuleID : 51819 - Type : FILE-MULTIMEDIA - Revision : 1
2019-04-27 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 49574 - Type : FILE-MULTIMEDIA - Revision : 4
2019-04-27 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 49573 - Type : FILE-MULTIMEDIA - Revision : 4
2014-01-10 RealNetworks RealPlayer realtext file bad version buffer overflow attempt
RuleID : 3823 - Type : FILE-MULTIMEDIA - Revision : 21
2014-01-10 RealNetworks RealPlayer realtext long URI request attempt
RuleID : 3822 - Type : SERVER-WEBAPP - Revision : 15
2014-11-16 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 31376 - Type : FILE-MULTIMEDIA - Revision : 5
2014-01-16 RealNetworks RealPlayer RealMedia URL length buffer overflow attempt
RuleID : 28962 - Type : FILE-MULTIMEDIA - Revision : 10
2014-01-16 RealNetworks RealPlayer RealMedia URL length buffer overflow attempt
RuleID : 28961 - Type : FILE-MULTIMEDIA - Revision : 9
2014-01-10 RealNetworks RealPlayer mpeg width integer memory underflow attempt
RuleID : 21112 - Type : FILE-MULTIMEDIA - Revision : 15
2014-01-10 RealNetworks RealPlayer IVR handling heap buffer overflow attempt
RuleID : 19127 - Type : FILE-MULTIMEDIA - Revision : 15
2014-01-10 RealNetworks RealPlayer IVR handling heap buffer overflow attempt
RuleID : 19126 - Type : FILE-MULTIMEDIA - Revision : 15

Nessus® Vulnerability Scanner

id Description
2014-07-10 Name: A multimedia application on the remote Windows host is affected by multiple m...
File: realplayer_17_0_10_8.nasl - Type: ACT_GATHER_INFO
2013-12-31 Name: A multimedia application on the remote Windows host is affected by a buffer o...
File: realplayer_17_0_4_61.nasl - Type: ACT_GATHER_INFO
2013-08-28 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_16_0_3_51.nasl - Type: ACT_GATHER_INFO
2013-03-20 Name: A multimedia application on the remote Windows host is affected by a buffer o...
File: realplayer_16_0_1_18.nasl - Type: ACT_GATHER_INFO
2012-12-18 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_16_0_0_282.nasl - Type: ACT_GATHER_INFO
2012-09-12 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_6_14.nasl - Type: ACT_GATHER_INFO
2012-05-17 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_4_53.nasl - Type: ACT_GATHER_INFO
2011-12-06 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_15_0_0_198.nasl - Type: ACT_GATHER_INFO
2011-04-14 Name: A multimedia application on the remote Windows host is affected by multiple v...
File: realplayer_12_0_1_647.nasl - Type: ACT_GATHER_INFO
2006-07-05 Name: The remote CentOS host is missing a security update.
File: centos_RHSA-2005-517.nasl - Type: ACT_GATHER_INFO
2005-10-05 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-826.nasl - Type: ACT_GATHER_INFO
2005-07-20 Name: The remote host is missing a vendor-supplied security patch
File: suse_SA_2005_037.nasl - Type: ACT_GATHER_INFO
2005-07-13 Name: The remote FreeBSD host is missing a security-related update.
File: freebsd_pkg_95ee96f2e48811d9bf22080020c11455.nasl - Type: ACT_GATHER_INFO
2005-07-06 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-200507-04.nasl - Type: ACT_GATHER_INFO
2005-06-24 Name: The remote Windows application is affected by multiple vulnerabilities.
File: realplayer_realtext_parsing_overflow.nasl - Type: ACT_GATHER_INFO
2005-06-24 Name: The remote Red Hat host is missing a security update.
File: redhat-RHSA-2005-517.nasl - Type: ACT_GATHER_INFO
2005-06-24 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2005-523.nasl - Type: ACT_GATHER_INFO