CVE-2005-2710

Real HelixPlayer & RealPlayer 10 - RCE

Title source: llm

Description

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by c0ntex · cremotelinux
https://www.exploit-db.com/exploits/1232

Scores

EPSS 0.5363
EPSS Percentile 98.0%

Details

Status published
Products (2)
realnetworks/helix_player
realnetworks/realplayer 10.0
Published Sep 27, 2005
Tracked Since Feb 18, 2026