CVE-2006-6847

RealPlayer 10.5 - DoS

Title source: llm

Description

An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmldoswindows
https://www.exploit-db.com/exploits/3030

Scores

EPSS 0.0510
EPSS Percentile 89.8%

Details

Status published
Products (8)
realnetworks/realplayer 10.5
realnetworks/realplayer 10.5_6.0.12.1016_beta
realnetworks/realplayer 10.5_6.0.12.1040
realnetworks/realplayer 10.5_6.0.12.1053
realnetworks/realplayer 10.5_6.0.12.1056
realnetworks/realplayer 10.5_6.0.12.1059
realnetworks/realplayer 10.5_6.0.12.1069
realnetworks/realplayer 10.5_6.0.12.1235
Published Dec 31, 2006
Tracked Since Feb 18, 2026