CVE-2011-2947
Realnetworks Realplayer - XSS
Title source: ruleDescription
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.
Scores
EPSS
0.0030
EPSS Percentile
52.7%
Classification
CWE
CWE-79
Status
published
Affected Products (19)
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
... and 4 more
Timeline
Published
Aug 18, 2011
Tracked Since
Feb 18, 2026