5
CVSSv2

CVE-2006-6847

Published: 31/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote malicious users to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 10.5_6.0.12.1053

realnetworks realplayer 10.5_6.0.12.1056

realnetworks realplayer 10.5_6.0.12.1235

realnetworks realplayer 10.5_6.0.12.1059

realnetworks realplayer 10.5_6.0.12.1069

realnetworks realplayer 10.5

realnetworks realplayer 10.5_6.0.12.1016_beta

realnetworks realplayer 10.5_6.0.12.1040

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol">----------------------------------------------------------------------------- RealPlayer 105 ierpplugdll multiple methods Denial of Service author: shinnai mail: shinnai[at]autistici[dot]org site: shinnaialtervistaorg Tested on Wi ...