Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2010-1317


Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.


Published

2010-04-20T15:30:00.583

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application realnetworks helix_dna_server 11.0 Yes
Application realnetworks helix_dna_server 11.1 Yes
Application realnetworks helix_dna_server 11.1.2 Yes
Application realnetworks helix_dna_server 11.1.3 Yes
Application realnetworks helix_dna_server 12.0 Yes
Application realnetworks helix_dna_server 13.0 Yes
Application realnetworks helix_server 11.0 Yes
Application realnetworks helix_server 11.1 Yes
Application realnetworks helix_server 12.0.0 Yes
Application realnetworks helix_server 13.0.0 Yes
Application realnetworks helix_server_mobile 11.0 Yes
Application realnetworks helix_server_mobile 12.0.0 Yes
Application realnetworks helix_server_mobile 13.0.0 Yes

References