VDB
CVE-2010-0416
CVE-2010-0416
PUBLISHED
Reported by redhat · Published February 18, 2010
Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a, n/a |
Timeline
- Feb 18, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- RHSA-2010:0094 vendor-advisoryx_refsource_REDHAT
- x_refsource_CONFIRM
- [common-cvs] 20070703 util hxurl.cpp,1.24.4.1,1.24.4.1.4.1 mailing-listx_refsource_MLIST
- 38450 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- oval:org.mitre.oval:def:10847 vdb-entrysignaturex_refsource_OVAL