Vulnerabilities > Realnetworks > Helix Server

DATE CVE VULNERABILITY TITLE RISK
2012-04-17 CVE-2012-2268 Improper Input Validation vulnerability in Realnetworks Helix Mobile Server and Helix Server
master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (unhandled exception and daemon crash) via a crafted Open-PDU request that triggers incorrect DisplayString processing, a different vulnerability than CVE-2012-1923.
network
low complexity
realnetworks CWE-20
5.0
2012-04-17 CVE-2012-2267 Permissions, Privileges, and Access Controls vulnerability in Realnetworks Helix Mobile Server and Helix Server
master.exe in the SNMP Master Agent in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to cause a denial of service (daemon crash) by establishing and closing a port-705 TCP connection, a different vulnerability than CVE-2012-1923.
network
low complexity
realnetworks CWE-264
5.0
2012-04-17 CVE-2012-1985 Cross-Site Request Forgery (CSRF) vulnerability in Realnetworks Helix Mobile Server and Helix Server
Cross-site request forgery (CSRF) vulnerability in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to hijack the authentication of administrators for requests that cause a denial of service (stack consumption and daemon crash) via a malformed URL.
6.8
2012-04-17 CVE-2012-1984 Cross-Site Scripting vulnerability in Realnetworks Helix Mobile Server and Helix Server
Multiple cross-site scripting (XSS) vulnerabilities in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2012-04-17 CVE-2012-1923 Cryptographic Issues vulnerability in Realnetworks Helix Mobile Server and Helix Server
RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x store passwords in cleartext under adm_b_db\users\, which allows local users to obtain sensitive information by reading a database.
local
low complexity
realnetworks CWE-310
2.1
2012-04-17 CVE-2012-0942 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks Helix Mobile Server and Helix Server
Buffer overflow in rn5auth.dll in RealNetworks Helix Server and Helix Mobile Server 14.x before 14.3.x allows remote attackers to execute arbitrary code via crafted authentication credentials.
network
low complexity
realnetworks CWE-119
7.5
2011-04-04 CVE-2010-4596 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks Helix Mobile Server and Helix Server
Stack-based buffer overflow in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via a long string in an RTSP request.
network
realnetworks CWE-119
critical
9.3
2011-04-04 CVE-2010-4235 USE of Externally-Controlled Format String vulnerability in Realnetworks Helix Mobile Server and Helix Server
Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.
network
low complexity
realnetworks CWE-134
critical
10.0
2010-04-20 CVE-2010-1319 Numeric Errors vulnerability in Realnetworks products
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.
network
low complexity
realnetworks CWE-189
critical
10.0
2010-04-20 CVE-2010-1318 Buffer Errors vulnerability in Realnetworks products
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
realnetworks CWE-119
critical
10.0