Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-1481


Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.


Published

2004-12-31T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

4.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application realnetworks helix_player 1.0 Yes
Application realnetworks realone_player 1.0 Yes
Application realnetworks realone_player 2.0 Yes
Application realnetworks realone_player 9.0.0.288 Yes
Application realnetworks realone_player 9.0.0.297 Yes
Application realnetworks realplayer - Yes
Application realnetworks realplayer 8.0 Yes
Application realnetworks realplayer 8.0 Yes
Application realnetworks realplayer 8.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0 Yes
Application realnetworks realplayer 10.0_6.0.12.690 Yes
Application realnetworks realplayer 10.5 Yes
Application realnetworks realplayer 10.5_6.0.12.1016 Yes
Application realnetworks realplayer 10.5_6.0.12.1040 Yes

References