CVE-2010-4235

EUVD-2010-4209
Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
realnetworkshelix_server
12.0.0
realnetworkshelix_server
12.0.1
realnetworkshelix_server
13.0.0
realnetworkshelix_server
13.1.1
realnetworkshelix_server
14.0.0
realnetworkshelix_server
14.0.1
realnetworkshelix_mobile_server
12.0
realnetworkshelix_mobile_server
13.1.1
realnetworkshelix_mobile_server
14.0.0
realnetworkshelix_mobile_server
14.0.1
𝑥
= Vulnerable software versions