RealNetworks / Realplayer
170 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-32291 | In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file. | HIGH | 8.8 | Jun 5, 2022 |
| CVE-2022-32270 | In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution.… | CRITICAL | 9.8 | Jun 3, 2022 |
| CVE-2022-32271 | In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to referen… | CRITICAL | 9.6 | Jun 3, 2022 |
| CVE-2022-32269 | In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This lea… | CRITICAL | 9.8 | Jun 3, 2022 |
| CVE-2017-9302 | RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp4 file. | MEDIUM | 5.5 | May 29, 2017 |
| CVE-2016-9018 | Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.… | MEDIUM | 5.5 | Oct 28, 2016 |
| CVE-2014-3113 | Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz ato… | HIGH | 9.3 | Jul 7, 2014 |
| CVE-2014-3444 | The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of… | HIGH | 9.3 | May 20, 2014 |
| CVE-2013-7260 | Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to… | HIGH | 7.5 | Jan 3, 2014 |
| CVE-2013-6877 | Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute ar… | HIGH | 9.3 | Dec 19, 2013 |
| CVE-2013-4974 | RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (… | HIGH | 9.3 | Aug 27, 2013 |
| CVE-2013-4973 | Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code… | HIGH | 9.3 | Aug 27, 2013 |
| CVE-2013-3299 | RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML docu… | MEDIUM | 4.3 | Jul 6, 2013 |
| CVE-2013-1750 | Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code vi… | HIGH | 9.3 | Mar 20, 2013 |
| CVE-2012-5691 | Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafte… | HIGH | 9.3 | Dec 19, 2012 |
| CVE-2012-5690 | RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allow remote attackers to execute arbitrary code via a RealAudio file that trigge… | HIGH | 9.3 | Dec 19, 2012 |
| CVE-2012-4987 | Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP file that t… | MEDIUM | 6.8 | Nov 4, 2012 |
| CVE-2012-3234 | RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 do not properly handle codec frame sizes in Re… | HIGH | 7.5 | Sep 12, 2012 |
| CVE-2012-2410 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to… | MEDIUM | 6.8 | Sep 12, 2012 |
| CVE-2012-2409 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to… | HIGH | 7.5 | Sep 12, 2012 |
| CVE-2012-2408 | The AAC SDK in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to caus… | MEDIUM | 6.8 | Sep 12, 2012 |
| CVE-2012-2407 | Buffer overflow in RealNetworks RealPlayer before 15.0.6.14, RealPlayer SP 1.0 through 1.1.5, and Mac RealPlayer before 12.0.1.1750 allows remote attackers to… | HIGH | 7.5 | Sep 12, 2012 |
| CVE-2012-2411 | Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a craft… | HIGH | 9.3 | May 18, 2012 |
| CVE-2012-2406 | RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, does not properly parse ASMRuleBook data in RealMedia files, which allows remote… | HIGH | 9.3 | May 18, 2012 |
| CVE-2012-1904 | mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Build 12.0.0.756 and earlier, allows remo… | MEDIUM | 4.3 | Mar 28, 2012 |
Showing 1 to 25 of 170 CVEs