[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2630Date: (C)2005-11-18   (M)2023-12-22


Heap-based buffer overflow in DUNZIP32.DLL for RealPlayer 8, 10, and 10.5 and RealOne Player 1 and 2 allows remote attackers to execute arbitrary code via a crafted RealPlayer Skin (RJS) file, a different vulnerability than CVE-2004-1094.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.1
Exploit Score: 4.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015184
SECTRACK-1015185
BID-15382
SREASON-170
SECUNIA-17514
SECUNIA-17860
OSVDB-18827
AD20051110b
EEYEB20050701
http://service.real.com/help/faq/security/051110_player/EN/
realplayer-rjs-zip-bo(23025)

CPE    2
cpe:/a:realnetworks:realplayer:10.5
cpe:/a:realnetworks:realplayer:10.0

© SecPod Technologies