CVE-2010-4235

Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
realnetworkshelix_server
12.0.0
realnetworkshelix_server
12.0.1
realnetworkshelix_server
13.0.0
realnetworkshelix_server
13.1.1
realnetworkshelix_server
14.0.0
realnetworkshelix_server
14.0.1
realnetworkshelix_mobile_server
12.0
realnetworkshelix_mobile_server
13.1.1
realnetworkshelix_mobile_server
14.0.0
realnetworkshelix_mobile_server
14.0.1
𝑥
= Vulnerable software versions