9.3
CVSSv2

CVE-2008-1309

Published: 12/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 prior to 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote malicious users to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 11

realnetworks realplayer 10.5

realnetworks realplayer

realnetworks realplayer 10.0

Exploits

This Metasploit module exploits a heap corruption vulnerability in the RealPlayer ActiveX control By sending a specially crafted string to the 'Console' property in the rmoc3260dll control, an attacker may be able to execute arbitrary code ...
## # $Id: realplayer_consolerb 9525 2010-06-15 07:18:08Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' cla ...
<!-- Real Player rmoc3260dll ActiveX Control Remote Code Execution Exploit(Heap Corruption) written by eb Tested on Windows XP SP2(fully patched) English, IE6, rmoc3260dll version 601045 Thanks to hdm and the Metasploit crew --> <html> <head> <title>Real Player rmoc3260dll ActiveX Control Remote Code Execution ...