Vulnerability Details CVE-2006-6847
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.042
EPSS Ranking 88.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-6847
-
cpe:2.3:a:realnetworks:realplayer:10.5
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1016_beta
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1040
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1053
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1056
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1059
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1069
-
cpe:2.3:a:realnetworks:realplayer:10.5_6.0.12.1235