[Forgot Password]
Login  Register Subscribe

23631

 
 

119105

 
 

98250

 
 

909

 
 

79281

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2007-2263

Date: (C)2007-10-31   (M)2017-11-17 


Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers.

CVSS Score: 9.3Access Vector: NETWORK
Exploit Score: 8.6Access Complexity: MEDIUM
Impact Score: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE





Reference:
SECTRACK-1018866
http://www.attrition.org/pipermail/vim/2007-October/001841.html
http://www.securityfocus.com/archive/1/archive/1/483110/100/0/threaded
BID-26214
BID-26284
SECUNIA-27361
OSVDB-38344
ADV-2007-3628
IAVM:2007-B-0035
http://service.real.com/realplayer/security/10252007_player/en/
http://www.zerodayinitiative.com/advisories/ZDI-07-061.html
realplayer-swf-bo(37436)

CWE    1
CWE-119
OVAL    2
oval:org.secpod.oval:def:14047
oval:org.secpod.oval:def:14055

© 2013 SecPod Technologies