
CVE-2018-13121
https://notcve.org/view.php?id=CVE-2018-13121
03 Jul 2018 — RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file. RealOnePlayer 2.0 Build 6.0.11.872, permite que atacantes remotos provoquen una denegación de servicio (acceso fuera de límites del array y cierre inesperado de la aplicación) mediante un archivo .aiff manipulado. • https://github.com/921580451/RealOnePlayer-sBug/issues/1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5081 – realplayer rm file heap overflow
https://notcve.org/view.php?id=CVE-2007-5081
31 Oct 2007 — Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file. Un desbordamiento de búfer en la región heap de la memoria en RealNetworks RealPlayer versiones 8, 10, 10.1 y posiblemente 10.5; RealOne Player versiones 1 y 2; y RealPlayer Enterprise, permite a atacantes remotos ejecutar código arbitrario por medio de un archivo RM diseñado. • http://osvdb.org/38340 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-5080
https://notcve.org/view.php?id=CVE-2007-5080
31 Oct 2007 — Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow. Desbordamiento de entero en RealNetworks RealPlayer 10 y 10.5, REalOne Player 1, y RealPlayer Enterprise para Windows permite a atacantes remotos ejecutar código de su elección mediante una etiqueta Lyrics3 2.00 manipulada en un archivo MP3, resultando en un ... • http://secunia.com/advisories/27361 • CWE-189: Numeric Errors •

CVE-2007-2263 – RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2007-2263
31 Oct 2007 — Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers. Un Desbordamiento de búfer en la región Heap de la memoria en RealNetworks RealPlayer las versiones 10.0, 10.1 y posiblemente 10.5, RealOne Player y RealPlayer Enterprise permiten que los atacantes remotos ejecuten código arbitrario por medio de un archivo SWF (Flash) con encabez... • http://osvdb.org/38344 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-2264 – RealPlayer RA Field Size File Processing Heap Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2007-2264
31 Oct 2007 — Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header. Un desbordamiento de búfer en la región Heap de la memoria en RealNetworks RealPlayer las versiones 8, 10, 10.1 y posiblemente 10.5; RealOne Player versiones 1 y 2; y RealPlayer Enterprise permite a los atacantes remotos ejecutar código arbitrario por med... • http://secunia.com/advisories/27361 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2007-4599 – RealNetworks RealPlayer PLS File Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2007-4599
31 Oct 2007 — Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file. Un desbordamiento de búfer en la región stack de la memoria en RealNetworks RealPlayer versiones 10 y posiblemente en 10.5, y RealOne Player versiones 1 y 2, para Windows, permite a atacantes remotos ejecutar código arbitrario por medio de un archivo de lista de reproducción (PLS) diseñada. This vulnerability... • http://osvdb.org/38341 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2006-1370
https://notcve.org/view.php?id=CVE-2006-1370
23 Mar 2006 — Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file. • http://secunia.com/advisories/19358 •

CVE-2005-2922
https://notcve.org/view.php?id=CVE-2005-2922
31 Dec 2005 — Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header. • http://secunia.com/advisories/19358 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2005-2936 – iDEFENSE Security Advisory 2005-11-15.2
https://notcve.org/view.php?id=CVE-2005-2936
18 Nov 2005 — Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file. The Microsoft Windows API includes the CreateProcess() function as a means to create a new process and it's primary thread. CreateProcessAsUser() is similar but allows for the process to be run in the security context of a particular user... • http://secunia.com/advisories/19358 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2005-2629 – RealNetworks RealOne Player/RealPlayer - '.RM' Local Stack Buffer Overflow
https://notcve.org/view.php?id=CVE-2005-2629
12 Nov 2005 — Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481. eEye Digital Security has discovered a critical vulnerability in RealPlayer. The vulnerability allows a remote attacker to reliably overwrite stack memory with arbitrary data... • https://www.exploit-db.com/exploits/26497 •