peter bassill · operator
$ cve CVE-2006-0323 JSON

CVE-2006-0323 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 16.7% (pctl 97)

Patch early

A public exploit exists.

Description

Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS16.74% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2006-03-23
Last modified2026-06-16

Affected (4)

VendorProduct
realnetworkshelix player
realnetworksrealone player
realnetworksrealplayer
realnetworksrhapsody

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD