
CVE-2010-0416 – Helix Player 11.0.2 - Encoded URI Processing Buffer Overflow
https://notcve.org/view.php?id=CVE-2010-0416
18 Feb 2010 — Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits. Desbordamiento de búfer en la función Unescape en common/util/hxurl.cpp y player/hxclientkit/src/CHXClientSink.cpp en Helix Player v1.0.6 y RealPlayer, permite a ... • https://www.exploit-db.com/exploits/33620 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2010-0417 – RealPlayer: rule book handling heap corruption
https://notcve.org/view.php?id=CVE-2010-0417
18 Feb 2010 — Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption. Desbordamiento de búfer en common/util/rlstate.cpp en Helix Player v1.0.6 y RealPlayer, permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) o posiblemente la ejecución de código d... • http://lists.helixcommunity.org/pipermail/common-cvs/2008-January/015484.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-4904 – RealPlayer 11 - '.au' Denial of Service
https://notcve.org/view.php?id=CVE-2007-4904
17 Sep 2007 — RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. RealNetworks RealPlayer 10.1.0.3114 y anteriores, y Helix Player 1.0.6.778 sobre Fedora Core 6 (FC6) y posiblemente otras plataformas, permite a atacantes remotos con la intervención del usuario provocar denegación de servicio (caida ... • https://www.exploit-db.com/exploits/4683 • CWE-189: Numeric Errors •

CVE-2005-0755
https://notcve.org/view.php?id=CVE-2005-0755
19 Apr 2005 — Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file. • http://marc.info/?l=bugtraq&m=111401615202987&w=2 •