Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2953

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2011-2953
Last Modified 05 Oct 2011 10:50:43
Published 18 Aug 2011 07:55:01
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-2953

Summary

An unspecified ActiveX control in the browser plugin in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to execute arbitrary code via unknown vectors, related to an out-of-bounds condition.

Vulnerable Systems

Application

  • Realnetworks Realplayer 11.0

  • Realnetworks Realplayer 11.1

  • Realnetworks Realplayer 14.0.0

  • Realnetworks Realplayer 14.0.1

  • Realnetworks Realplayer 14.0.2

  • Realnetworks Realplayer 14.0.3

  • Realnetworks Realplayer 14.0.4

  • Realnetworks Realplayer 14.0.5

  • Realnetworks Realplayer 2.0

  • Realnetworks Realplayer 2.1

  • Realnetworks Realplayer 2.1.2

  • Realnetworks Realplayer 2.1.3

  • Realnetworks Realplayer 2.1.4

  • Realnetworks Realplayer 2.1.5

  • Realnetworks Realplayer Sp 1.0.0

  • Realnetworks Realplayer Sp 1.0.1

  • Realnetworks Realplayer Sp 1.0.2

  • Realnetworks Realplayer Sp 1.0.5

  • Realnetworks Realplayer Sp 1.1

  • Realnetworks Realplayer Sp 1.1.1

  • Realnetworks Realplayer Sp 1.1.2

  • Realnetworks Realplayer Sp 1.1.3

  • Realnetworks Realplayer Sp 1.1.4

  • Realnetworks Realplayer Sp 1.1.5


References

SECTRACK - 1025943

CONFIRM - http://service.real.com/realplayer/security/08162011_player/en/


Last Updated: 27 May 2016 10:57:13