CVE-2010-4390

RealPlayer 11.0-11.1 and RealPlayer SP 1.0-1.1.5 - Heap-Based Buffer Overflow via IVR File Header

Title source: llm
STIX 2.1

Description

Multiple heap-based buffer overflows in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and Linux RealPlayer 11.0.2.1744 allow remote attackers to have an unspecified impact via a crafted header in an IVR file.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/69850
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024861

Scores

EPSS 0.0135
EPSS Percentile 80.3%

Details

CWE
CWE-119
Status published
Products (18)
realnetworks/realplayer 11.0
realnetworks/realplayer 11.0.1
realnetworks/realplayer 11.0.2
realnetworks/realplayer 11.0.3
realnetworks/realplayer 11.0.4
realnetworks/realplayer 11.0.5
realnetworks/realplayer 11.1
realnetworks/realplayer 11.0.2.1744
realnetworks/realplayer_sp 1.0.0
realnetworks/realplayer_sp 1.0.1
... and 8 more
Published Dec 14, 2010
Tracked Since Feb 18, 2026