VDB
CVE-2006-0323
CVE-2006-0323
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations.
EPSS 16.74% · 97.0th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
16.74%
97.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| realnetworks | realplayer | 10.0.6, 10.5, 10.0 |
| realnetworks | helix_player | |
| realnetworks | rhapsody | 3 |
| N/A | N/A | |
| n/a | n/a | n/a |
| realnetworks | realone_player |
Timeline
- Mar 23, 2006 CVE Published
- Mar 27, 2006 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- 19358 third-party-advisory
- 690 third-party-advisory
- 19365 third-party-advisory
- 20060411 Realplayer .SWF Multiple Remote Memory Corruption Vulnerabilities mailing-list
- RHSA-2006:0257 vendor-advisory
- GLSA-200603-24 vendor-advisory
- realnetworks-swf-bo(25408) vdb
- 19390 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-0323 advisory
- http://www.kb.cert.org/vuls/id/231028 url
- http://www.service.real.com/realplayer/security/03162006_player/en url
- http://service.real.com/realplayer/security advisory
- http://secunia.com/advisories/19362 patch
- http://securitytracker.com/id?1015806 technical
- http://www.securityfocus.com/bid/17202 exploit
- http://www.service.real.com/realplayer/security/03162006_player/en/ patch
- http://www.vupen.com/english/advisories/2006/1057 technical
- http://www.novell.com/linux/security/advisories/2006_18_realplayer.html patch