CVE-2010-3747 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 34.8% (pctl 98)
Patch early
A public exploit exists.
Description
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during parsing of a CDDA URI, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer dereference and application crash) via a long URI.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 34.79% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-10-19 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| realnetworks | realplayer |
| realnetworks | realplayer sp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | RealNetworks RealPlayer - CDDA URI Initialization (Metasploit) | 2011-03-17 |
References
- http://securityreason.com/securityalert/8147
- http://service.real.com/realplayer/security/10152010_player/en/
- http://www.securityfocus.com/bid/44144
- http://www.zerodayinitiative.com/advisories/ZDI-10-210/
- http://securityreason.com/securityalert/8147
- http://service.real.com/realplayer/security/10152010_player/en/
- http://www.securityfocus.com/bid/44144
- http://www.zerodayinitiative.com/advisories/ZDI-10-210/
→ the Explorer · watch your stack · NVD