CVE-2011-2947

Realnetworks Realplayer - XSS

Title source: rule

Description

Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.

Scores

EPSS 0.0030
EPSS Percentile 52.7%

Classification

CWE
CWE-79
Status published

Affected Products (19)

realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
realnetworks/realplayer_sp
... and 4 more

Timeline

Published Aug 18, 2011
Tracked Since Feb 18, 2026