9.3

CVE-2005-2922

Exploit

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RealnetworksHelix Player Version10.0 Editionlinux
RealnetworksHelix Player Version10.0.1 Editionlinux
RealnetworksHelix Player Version10.0.2 Editionlinux
RealnetworksHelix Player Version10.0.3 Editionlinux
RealnetworksHelix Player Version10.0.4 Editionlinux
RealnetworksHelix Player Version10.0.5 Editionlinux
RealnetworksHelix Player Version10.0.6 Editionlinux
RealnetworksRealone Player Version0.288 Editionmac_os_x
RealnetworksRealone Player Version0.297 Editionmac_os_x
RealnetworksRealone Player Version1.0
RealnetworksRealone Player Version2.0
RealnetworksRealplayer Editionenterprise
RealnetworksRealplayer Version8.0 Editionwin32
RealnetworksRealplayer Version10.0
RealnetworksRealplayer Version10.0.0.305 Editionmac_os
RealnetworksRealplayer Version10.0.0.331 Editionmac_os
RealnetworksRealplayer Version10.0.1 Editionlinux
RealnetworksRealplayer Version10.0.2 Editionlinux
RealnetworksRealplayer Version10.0.3 Editionlinux
RealnetworksRealplayer Version10.0.4 Editionlinux
RealnetworksRealplayer Version10.0.5 Editionlinux
RealnetworksRealplayer Version10.0.6 Editionlinux
RealnetworksRealplayer Version10.5
RealnetworksRealplayer Version10.5_6.0.12.1040
RealnetworksRealplayer Version10.5_6.0.12.1053
RealnetworksRealplayer Version10.5_6.0.12.1056
RealnetworksRealplayer Version10.5_6.0.12.1059
RealnetworksRealplayer Version10.5_6.0.12.1069
RealnetworksRealplayer Version10.5_6.0.12.1235
RealnetworksRhapsody Version3.0
RealnetworksRhapsody Version3.0_build_0.815
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.36% 0.878
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.