9.3
CVSSv2

CVE-2007-5400

Published: 28/07/2008 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the Shockwave Flash (SWF) frame handling in RealNetworks RealPlayer 10.5 Build 6.0.12.1483 might allow remote malicious users to execute arbitrary code via a crafted SWF file.

Vulnerable Product Search on Vulmon Subscribe to Product

real realplayer 10.1

realnetworks realplayer 10.5

realnetworks realplayer 10.0

Recent Articles

High-priority patch fixes critical vulns in RealPlayer
The Register • Dan Goodin • 25 Jul 2008

Available in Windows, Mac and Linux

RealNetworks has issued an update that patches four security holes in its RealPlayer jukebox program, including a critical flaw that vulnerability tracker Secunia published today. The company says versions for Windows, Mac, Linux operating systems are all vulnerable to at least one of the flaws and that users should update as soon as possible. Among the bugs that are fixed is a flaw within the handling of frames in Shockwave Flash (SWF) files that can be triggered by a heap-based buffer overflow...