// For flags

CVE-2003-0726

RealOne Player 1.0/2.0/6.0.10/6.0.11 - '.SMIL' File Script Execution

Severity Score

5.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-08-19 First Exploit
  • 2003-09-02 CVE Reserved
  • 2003-09-03 CVE Published
  • 2023-03-11 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Realnetworks
Search vendor "Realnetworks"
Realone Desktop Manager
Search vendor "Realnetworks" for product "Realone Desktop Manager"
*-
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Enterprise Desktop
Search vendor "Realnetworks" for product "Realone Enterprise Desktop"
6.0.11.774
Search vendor "Realnetworks" for product "Realone Enterprise Desktop" and version "6.0.11.774"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Player
Search vendor "Realnetworks" for product "Realone Player"
2.0
Search vendor "Realnetworks" for product "Realone Player" and version "2.0"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Player
Search vendor "Realnetworks" for product "Realone Player"
6.0.10.505
Search vendor "Realnetworks" for product "Realone Player" and version "6.0.10.505"
gold
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Player
Search vendor "Realnetworks" for product "Realone Player"
6.0.11.818
Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.818"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Player
Search vendor "Realnetworks" for product "Realone Player"
6.0.11.830
Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.830"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Player
Search vendor "Realnetworks" for product "Realone Player"
6.0.11.841
Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.841"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Realone Player
Search vendor "Realnetworks" for product "Realone Player"
6.0.11.853
Search vendor "Realnetworks" for product "Realone Player" and version "6.0.11.853"
-
Affected