Vulnerabilities > Realnetworks > Critical

DATE CVE VULNERABILITY TITLE RISK
2010-08-30 CVE-2010-0117 Unspecified vulnerability in Realnetworks Realplayer and Realplayer SP
RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows do not properly handle dimensions during YUV420 transformations, which might allow remote attackers to execute arbitrary code via crafted MP4 content.
network
realnetworks microsoft
critical
9.3
2010-08-30 CVE-2010-0116 Numeric Errors vulnerability in Realnetworks Realplayer and Realplayer SP
Integer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows might allow remote attackers to execute arbitrary code via a crafted QCP file that triggers a heap-based buffer overflow.
network
realnetworks microsoft CWE-189
critical
9.3
2010-04-20 CVE-2010-1319 Numeric Errors vulnerability in Realnetworks products
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.
network
low complexity
realnetworks CWE-189
critical
10.0
2010-04-20 CVE-2010-1318 Buffer Errors vulnerability in Realnetworks products
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
realnetworks CWE-119
critical
10.0
2010-01-25 CVE-2009-4257 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks products
Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths.
network
realnetworks microsoft apple CWE-119
critical
9.3
2010-01-25 CVE-2009-4248 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks products
Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted RTSP SET_PARAMETER request.
network
realnetworks microsoft apple CWE-119
critical
9.3
2010-01-25 CVE-2009-4247 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks products
Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an ASM RuleBook with a large number of rules, related to an "array overflow." Specific affected release information can be found from RealNetworks at: http://service.real.com/realplayer/security/01192010_player/en/
network
realnetworks microsoft apple CWE-119
critical
9.3
2010-01-25 CVE-2009-4246 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks products
Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows user-assisted remote attackers to execute arbitrary code via a malformed .RJS skin file that contains a web.xmb file with crafted length values.
network
realnetworks microsoft apple CWE-119
critical
9.3
2010-01-25 CVE-2009-4245 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks products
Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.
network
realnetworks microsoft apple CWE-119
critical
9.3
2010-01-25 CVE-2009-4244 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks products
Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via an SIPR codec field with a small length value that triggers incorrect memory allocation.
network
realnetworks microsoft apple CWE-119
critical
9.3