5
CVSSv2

CVE-2006-6847

Published: 31/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote malicious users to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 10.5 6.0.12.1069

realnetworks realplayer 10.5 6.0.12.1016 beta

realnetworks realplayer 10.5 6.0.12.1053

realnetworks realplayer 10.5 6.0.12.1056

realnetworks realplayer 10.5 6.0.12.1235

realnetworks realplayer 10.5 6.0.12.1059

realnetworks realplayer 10.5

realnetworks realplayer 10.5 6.0.12.1040

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol">----------------------------------------------------------------------------- RealPlayer 105 ierpplugdll multiple methods Denial of Service author: shinnai mail: shinnai[at]autistici[dot]org site: shinnaialtervistaorg Tested on Wi ...