Vulnerabilities > Realnetworks > Helix Server > 12.0.0

DATE CVE VULNERABILITY TITLE RISK
2011-04-04 CVE-2010-4596 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks Helix Mobile Server and Helix Server
Stack-based buffer overflow in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via a long string in an RTSP request.
network
realnetworks CWE-119
critical
9.3
2011-04-04 CVE-2010-4235 USE of Externally-Controlled Format String vulnerability in Realnetworks Helix Mobile Server and Helix Server
Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.
network
low complexity
realnetworks CWE-134
critical
10.0
2010-04-20 CVE-2010-1319 Numeric Errors vulnerability in Realnetworks products
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.
network
low complexity
realnetworks CWE-189
critical
10.0
2010-04-20 CVE-2010-1318 Buffer Errors vulnerability in Realnetworks products
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
realnetworks CWE-119
critical
10.0
2010-04-20 CVE-2010-1317 Buffer Errors vulnerability in Realnetworks Helix DNA Server, Helix Server and Helix Server Mobile
Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.
network
low complexity
realnetworks CWE-119
7.5
2009-07-20 CVE-2009-2534 Improper Input Validation vulnerability in Realnetworks Helix Server and Helix Server Mobile
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.
network
low complexity
realnetworks CWE-20
5.0
2009-07-20 CVE-2009-2533 Improper Input Validation vulnerability in Realnetworks Helix Server and Helix Server Mobile
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.
network
low complexity
realnetworks CWE-20
5.0
2009-01-20 CVE-2008-5911 Buffer Errors vulnerability in Realnetworks Helix Server and Helix Server Mobile
Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.
network
low complexity
realnetworks CWE-119
critical
10.0