cbcvebase.

Realnetworks Helix Player vulnerabilities

17 known vulnerabilities affecting realnetworks/helix_player.

Total CVEs
17
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH1MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2007-3410P3CRITICALCVSS 9.3PoCv10.0.5v10.0.6+3 more2007-06-26
CVE-2007-3410 [CRITICAL] CWE-119 CVE-2007-3410: Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.
nvd
CVE-2010-0416P3HIGHCVSS 7.5PoCv1.0.62010-02-18
CVE-2010-0416 [HIGH] CWE-119 CVE-2010-0416: Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClie Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.
nvd
CVE-2005-2629P3MEDIUMCVSS 5.1PoCv1.0v1.0.1+4 more2005-11-18
CVE-2005-2629 [MEDIUM] CVE-2005-2629: Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Playe Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability than CVE-2004-1481.
nvd
CVE-2009-4242P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4242 [CRITICAL] CWE-119 CVE-2009-4242: Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/g Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/gifcodec.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attacke
nvd
CVE-2009-4257P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4257 [CRITICAL] CWE-119 CVE-2009-4257: Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealP Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbi
nvd
CVE-2009-4244P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4244 [CRITICAL] CWE-119 CVE-2009-4244: Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12 Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via an SIPR codec field with a small length value that t
nvd
CVE-2009-4247P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4247 [CRITICAL] CWE-119 CVE-2009-4247: Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allows remot
nvd
CVE-2009-4246P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4246 [CRITICAL] CWE-119 CVE-2009-4246: Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.1 Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows user-assisted remote attackers to execute arbitrary code via a malformed .RJS skin file that contains a w
nvd
CVE-2009-4241P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4241 [CRITICAL] CWE-119 CVE-2009-4241: Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12 Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger hea
nvd
CVE-2009-4248P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4248 [CRITICAL] CWE-119 CVE-2009-4248: Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol. Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a d
nvd
CVE-2009-4245P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4245 [CRITICAL] CWE-119 CVE-2009-4245: Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12 Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a
nvd
CVE-2009-4243P3CRITICALCVSS 9.3v10.0v11.0.0+1 more2010-01-25
CVE-2009-4243 [CRITICAL] CWE-119 CVE-2009-4243: RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 th RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to have an unspecified impact via a crafted media file that uses HTTP chunked transfer coding, related to an "overflow."
nvd
CVE-2005-2922P3CRITICALCVSS 9.3v10.0v10.0.1+5 more2005-12-31
CVE-2005-2922 [CRITICAL] CWE-119 CVE-2005-2922: Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions inc Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length
nvd
CVE-2007-4904P4MEDIUMCVSS 4.3PoCv1.0.62007-09-17
CVE-2007-4904 [MEDIUM] CWE-189 CVE-2007-4904: RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) a RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.
nvd
CVE-2010-0417P4MEDIUMCVSS 5.0v1.0.62010-02-18
CVE-2010-0417 [MEDIUM] CWE-119 CVE-2010-0417: Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attack Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.
nvd
CVE-2004-1481P4MEDIUMCVSS 5.1v1.02004-12-31
CVE-2004-1481 [MEDIUM] CVE-2004-1481: Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow.
nvd
CVE-2005-0755P4MEDIUMCVSS 5.1≤ 10.0.32005-04-19
CVE-2005-0755 [MEDIUM] CVE-2005-0755: Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Pla Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.
nvd
Realnetworks Helix Player vulnerabilities | cvebase