Skip to main content

Vendor archive

realnetworks CVEs

Beta · best-effort

215 CVEs tagged to vendor realnetworks130 Critical, 29 High, 50 Medium, 6 Low, 0 Unrated.

CVE-2022-32291

Published Jun 5, 2022

In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32271

Published Jun 3, 2022

In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that conta…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-32270

Published Jun 3, 2022

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-32269

Published Jun 3, 2022

In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-13121

Published Jul 3, 2018

RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9302

Published May 29, 2017

RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp4 file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9018

Published Oct 28, 2016

Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafte…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2604

Published Jan 12, 2015

RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2603

Published Jan 12, 2015

The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid paramete…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3113

Published Jul 7, 2014

Multiple buffer overflows in RealNetworks RealPlayer before 17.0.10.8 allow remote attackers to execute arbitrary code via a malformed (1) elst or (2) stsz atom in an MP4 file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3444

Published May 20, 2014

The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write acce…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-7260

Published Jan 3, 2014

Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6877

Published Dec 19, 2013

Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a l…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3299

Published Jul 6, 2013

RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing Java…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4987

Published Nov 4, 2012

Stack-based buffer overflow in RealNetworks RealPlayer 15.0.5.109 allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP file that triggers incorrect pr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 215 CVEsPage 1 of 9