CVE-2010-3000 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7.5% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.5% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-189 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-08-30 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | windows |
| realnetworks | realplayer |
| realnetworks | realplayer sp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RealPlayer - FLV Parsing Integer Overflow | 2010-09-13 |
References
- http://secunia.com/advisories/41096
- http://secunia.com/advisories/41154
- http://service.real.com/realplayer/security/08262010_player/en/
- http://www.securityfocus.com/archive/1/513383/100/0/threaded
- http://www.securitytracker.com/id?1024370
- http://www.vupen.com/english/advisories/2010/2216
- http://www.zerodayinitiative.com/advisories/ZDI-10-167
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61423
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6651
- http://secunia.com/advisories/41096
- http://secunia.com/advisories/41154
- http://service.real.com/realplayer/security/08262010_player/en/
- http://www.securityfocus.com/archive/1/513383/100/0/threaded
- http://www.securitytracker.com/id?1024370
- http://www.vupen.com/english/advisories/2010/2216
- http://www.zerodayinitiative.com/advisories/ZDI-10-167
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61423
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6651
→ the Explorer · watch your stack · NVD