CVE-2011-2947
published 2011-08-18CVE-2011-2947: Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.06%
60.4th percentile
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
| realnetworks | realplayer_sp | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-94hx-9jmq-hhfq: Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-1221 [MEDIUM] CWE-79 GHSA-94hx-9jmq-hhfq: Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document, a different vulnerability than CVE-2011-2947.
GHSA
GHSA-fxp2-hpw9-6j23: Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11
ghsa_unreviewed·2022-05-17
CVE-2011-2947 [MEDIUM] CWE-79 GHSA-fxp2-hpw9-6j23: Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to inject arbitrary web script or HTML in the Local Zone via a local HTML document.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://service.real.com/realplayer/security/08162011_player/en/http://www.securitytracker.com/id?1025943http://zerodayinitiative.com/advisories/ZDI-11-269/http://service.real.com/realplayer/security/08162011_player/en/http://www.securitytracker.com/id?1025943http://zerodayinitiative.com/advisories/ZDI-11-269/
2011-08-18
Published