VDB
CVE-2005-2710
CVE-2005-2710
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.
EPSS 13.18% · 96.3th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
13.18%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| realnetworks | helix_player | |
| realnetworks | realplayer | 10.0 |
| n/a | n/a | n/a |
Timeline
- CVE Published
- Jul 30, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- DSA-826 vendor-advisory
- 20050926 RealPlayer && HelixPlayer Remote Format String mailing-list
- oval:org.mitre.oval:def:11015 vdb
- 20050926 RealPlayer && HelixPlayer Remote Format String Exploit mailing-list
- 17127 third-party-advisory
- VU#361181 third-party-advisory
- 16961 third-party-advisory
- RHSA-2005:788 vendor-advisory
- 17116 third-party-advisory
- SUSE-SA:2005:059 vendor-advisory
- http://www.open-security.org/advisories/13 url
- RHSA-2005:762 vendor-advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=168078 advisory
- http://secunia.com/advisories/16954 technical
- http://securityreason.com/securityalert/27 technical
- http://www.gentoo.org/security/en/glsa/glsa-200510-07.xml technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-2710 advisory
- http://secunia.com/advisories/16981 url
- http://securityreason.com/securityalert/41 url
- http://www.idefense.com/application/poi/display?id=311&type=vulnerabilities url