peter bassill · operator
$ cve CVE-2010-3000 JSON

CVE-2010-3000 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 7.5% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS7.5% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2010-08-30
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftwindows
realnetworksrealplayer
realnetworksrealplayer sp

Public exploits

SourceTitleDate
exploit-dbRealPlayer - FLV Parsing Integer Overflow2010-09-13

References

→ the Explorer  ·  watch your stack  ·  NVD