Vulnerabilities > CVE-2006-6847 - Remote Denial of Service vulnerability in RealNetworks RealPlayer IERPPLUG.DLL ActiveX Control

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
realnetworks
exploit available

Summary

An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.

Exploit-Db

descriptionRealPlayer 10.5 ierpplug.dll Internet Explorer Denial of Service Exploit. CVE-2006-6847. Dos exploit for windows platform
fileexploits/windows/dos/3030.html
idEDB-ID:3030
last seen2016-01-31
modified2006-12-28
platformwindows
port
published2006-12-28
reportershinnai
sourcehttps://www.exploit-db.com/download/3030/
titleRealPlayer 10.5 ierpplug.dll Internet Explorer 7 - Denial of Service Exploit
typedos