CVE-2009-4241

Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger heap memory corruption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
realnetworksrealplayer
10.0
realnetworksrealplayer
10.5
realnetworksrealplayer
11.0
realnetworksrealplayer
11.0.1
realnetworksrealplayer
11.0.2
realnetworksrealplayer
11.0.3
realnetworksrealplayer
11.0.4
realnetworksrealplayer
11.0.5
realnetworksrealplayer_enterprise
*
realnetworksrealplayer_sp
1.0.0
realnetworksrealplayer_sp
1.0.1
realnetworksrealplayer
10.0
realnetworksrealplayer
10.1
realnetworksrealplayer
11.0
realnetworksrealplayer
11.0.1
realnetworkshelix_player
10.0
realnetworkshelix_player
11.0.0
realnetworkshelix_player
11.0.1
realnetworksrealplayer
10.0
realnetworksrealplayer
11.0.0
realnetworksrealplayer
11.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
realplay
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
ignored
realplayer
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
dapper
ignored