CVE-2006-0323
Published Mar 23, 2006
Last updated 6 years ago
Overview
- Description
- Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:realnetworks:helix_player:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B288E1C-4511-482A-B39D-E6BB9585AF18" }, { "criteria": "cpe:2.3:a:realnetworks:realone_player:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5695A49-561F-434E-92AE-AEF13162BD78" }, { "criteria": "cpe:2.3:a:realnetworks:realplayer:10.0:gold:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1E6B49C-BDF7-41A8-A6B4-4AA1A47C87FA" }, { "criteria": "cpe:2.3:a:realnetworks:realplayer:10.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B857582E-8B1A-4ED4-8C0C-9D8D5BDD1E31" }, { "criteria": "cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "348F3214-E5C2-4D39-916F-1B0263D13F40" }, { "criteria": "cpe:2.3:a:realnetworks:rhapsody:3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91156125-28D3-498A-9521-F748D9FA7FF7" } ], "operator": "OR" } ] } ]