Vulnerabilities > CVE-2010-3000 - Numeric Errors vulnerability in Realnetworks Realplayer and Realplayer SP

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
realnetworks
microsoft
CWE-189
critical
nessus
exploit available

Summary

Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionMOAUB #13 - RealPlayer FLV Parsing Integer Overflow. CVE-2010-3000. Dos exploit for windows platform
idEDB-ID:14992
last seen2016-02-01
modified2010-09-13
published2010-09-13
reporterAbysssec
sourcehttps://www.exploit-db.com/download/14992/
titleRealPlayer - FLV Parsing Integer Overflow

Nessus

NASL familyWindows
NASL idREALPLAYER_12_0_0_879.NASL
descriptionAccording to its build number, the installed version of RealPlayer on the remote Windows host has multiple buffer overflow vulnerabilities : - A RealPlayer malformed
last seen2020-06-01
modified2020-06-02
plugin id48907
published2010-08-27
reporterThis script is Copyright (C) 2010-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/48907
titleRealPlayer for Windows < Build 12.0.0.879 Multiple Vulnerabilities

Oval

accepted2010-11-01T04:00:03.580-04:00
classvulnerability
contributors
nameSecPod Team
organizationSecPod Technologies
definition_extensions
commentRealPlayer or RealPlayer SP is installed on the system
ovaloval:org.mitre.oval:def:7330
descriptionMultiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.
familywindows
idoval:org.mitre.oval:def:6651
statusaccepted
submitted2010-09-22T01:48:18
titleMultiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4
version5

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/93807/moaub-realplayer.txt
idPACKETSTORM:93807
last seen2016-12-05
published2010-09-14
reporterAbysssec
sourcehttps://packetstormsecurity.com/files/93807/Month-Of-Abysssec-Undisclosed-Bugs-RealPlayer.html
titleMonth Of Abysssec Undisclosed Bugs - RealPlayer

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:69834
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-69834
titleRealPlayer - FLV Parsing Integer Overflow