Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-4256

Опубликовано: 24 нояб. 2011
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:realnetworks:realplayer:*:*:mac_os:*:*:*:*:*
Версия до 12.0.0.1701 (включая)
cpe:2.3:a:realnetworks:realplayer:7.0:*:mac_os:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:8.0:*:mac_os:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.0:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.0.0.305:*:mac_os:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.0.0.331:*:mac_os:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.1:*:mac_os_x:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:12.0.0.1569:*:mac_os:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:realnetworks:realplayer:*:*:*:*:*:*:*:*
Версия до 14.0.7 (включая)
cpe:2.3:a:realnetworks:realplayer:4:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:5:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:6:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:7:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:8:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.1:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.2:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.2.1744:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.2.2315:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.3:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.4:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.0.5:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11.1.3:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:11_build_6.0.14.748:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:12.0.0.1444:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:12.0.0.1548:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.1.609:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.1.633:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.3:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.4:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.5:*:*:*:*:*:*:*
cpe:2.3:a:realnetworks:realplayer:14.0.6:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04969
Низкий

10 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
больше 3 лет назад

The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors.

EPSS

Процентиль: 89%
0.04969
Низкий

10 Critical

CVSS2

Дефекты

CWE-94