CVE-2022-32291
- EPSS 0.47%
- Published 05.06.2022 22:15:08
- Last modified 21.11.2024 07:06:06
In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.
CVE-2022-32269
- EPSS 1.12%
- Published 03.06.2022 06:15:07
- Last modified 21.11.2024 07:06:04
In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.
CVE-2022-32270
- EPSS 4.06%
- Published 03.06.2022 06:15:07
- Last modified 21.11.2024 07:06:04
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL plantin...
CVE-2022-32271
- EPSS 2.72%
- Published 03.06.2022 06:15:07
- Last modified 21.11.2024 07:06:04
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. ...
CVE-2017-9302
- EPSS 0.24%
- Published 29.05.2017 19:29:00
- Last modified 20.04.2025 01:37:25
RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp4 file.
CVE-2016-9018
- EPSS 1.39%
- Published 28.10.2016 15:59:18
- Last modified 12.04.2025 10:46:40
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.
CVE-2014-3113
- EPSS 12.87%
- Published 07.07.2014 11:01:30
- Last modified 12.04.2025 10:46:40
Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.
CVE-2014-3444
- EPSS 25.9%
- Published 20.05.2014 11:13:38
- Last modified 12.04.2025 10:46:40
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.
CVE-2013-7260
- EPSS 78.26%
- Published 03.01.2014 20:55:06
- Last modified 11.04.2025 00:51:21
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML...
CVE-2013-6877
- EPSS 34.98%
- Published 19.12.2013 22:55:04
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a long string in the TRACKID element of an RMP file, a different vulnerabi...