9.3
CVSSv2

CVE-2007-3410

Published: 26/06/2007 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 up to and including 10.0.8, allows remote malicious users to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 10.0

realnetworks realplayer enterprise

realnetworks helix player 10.5-gold

realnetworks realone player

realnetworks realplayer 10.1

realnetworks helix player 10.0.8

realnetworks helix player 10.0.7

realnetworks helix player 10.0.6

realnetworks helix player 10.0.5

realnetworks realplayer 10.5

Exploits

<!-- author: axis site: wwwph4nt0morg --> <smil xmlns="wwww3org/2000/SMIL20/CR/Language"> <body> <par> <img src="/1jpg" begin="wallclock(12:00:00999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999+9)" dur=" ...