9.3
CVSSv2

CVE-2008-3066

Published: 28/07/2008 Updated: 30/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in a certain ActiveX control in rjbdll.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, and RealPlayer 10.5 before build 6.0.12.1675 allows remote malicious users to execute arbitrary code by importing a file into a media library and then deleting this file.

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 10.0

realnetworks realplayer 10.5

Recent Articles

High-priority patch fixes critical vulns in RealPlayer
The Register • Dan Goodin • 25 Jul 2008

Available in Windows, Mac and Linux

RealNetworks has issued an update that patches four security holes in its RealPlayer jukebox program, including a critical flaw that vulnerability tracker Secunia published today. The company says versions for Windows, Mac, Linux operating systems are all vulnerable to at least one of the flaws and that users should update as soon as possible. Among the bugs that are fixed is a flaw within the handling of frames in Shockwave Flash (SWF) files that can be triggered by a heap-based buffer overflow...