peter bassill · operator
$ cve CVE-2010-3747 JSON

CVE-2010-3747 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 34.8% (pctl 98)

Patch early

A public exploit exists.

Description

An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during parsing of a CDDA URI, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and application crash) via a long URI.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS34.79% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2010-10-19
Last modified2026-06-16

Affected (2)

VendorProduct
realnetworksrealplayer
realnetworksrealplayer sp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD