CVE-2010-3750

RealPlayer 11.0-11.1 and RealPlayer SP 1.0-1.1.4 - Remote Code Execution via Crafted NVP Elements in Media File

Title source: llm
STIX 2.1

Description

rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, which allows remote attackers to execute arbitrary code via crafted Name Value Property (NVP) elements in logical streams in a media file.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/44144
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-10-212/

Scores

EPSS 0.0152
EPSS Percentile 81.5%

Details

CWE
CWE-20
Status published
Products (17)
realnetworks/realplayer 11.0
realnetworks/realplayer 11.0.1
realnetworks/realplayer 11.0.2
realnetworks/realplayer 11.0.3
realnetworks/realplayer 11.0.4
realnetworks/realplayer 11.0.5
realnetworks/realplayer 11.1
realnetworks/realplayer 2.1.2
realnetworks/realplayer_sp 1.0.0
realnetworks/realplayer_sp 1.0.1
... and 7 more
Published Oct 19, 2010
Tracked Since Feb 18, 2026