Vulnerability Details CVE-2012-0926
The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows remote attackers to execute arbitrary code via a crafted RV10 RealVideo video stream.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.034
EPSS Ranking 86.7%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2012-0926
-
cpe:2.3:a:realnetworks:realplayer:11.0
-
cpe:2.3:a:realnetworks:realplayer:11.0.1
-
cpe:2.3:a:realnetworks:realplayer:11.0.2
-
cpe:2.3:a:realnetworks:realplayer:11.0.2.1744
-
cpe:2.3:a:realnetworks:realplayer:11.0.2.2315
-
cpe:2.3:a:realnetworks:realplayer:11.0.3
-
cpe:2.3:a:realnetworks:realplayer:11.0.4
-
cpe:2.3:a:realnetworks:realplayer:11.0.5
-
cpe:2.3:a:realnetworks:realplayer:11.1
-
cpe:2.3:a:realnetworks:realplayer:11.1.3
-
cpe:2.3:a:realnetworks:realplayer:11_build_6.0.14.748
-
cpe:2.3:a:realnetworks:realplayer:14.0.0
-
cpe:2.3:a:realnetworks:realplayer:14.0.1
-
cpe:2.3:a:realnetworks:realplayer:14.0.1.609
-
cpe:2.3:a:realnetworks:realplayer:14.0.1.633
-
cpe:2.3:a:realnetworks:realplayer:14.0.2
-
cpe:2.3:a:realnetworks:realplayer:14.0.3
-
cpe:2.3:a:realnetworks:realplayer:14.0.4
-
cpe:2.3:a:realnetworks:realplayer:14.0.5
-
cpe:2.3:a:realnetworks:realplayer:14.0.6
-
cpe:2.3:a:realnetworks:realplayer:14.0.7
-
cpe:2.3:a:realnetworks:realplayer:15.0.0
-
cpe:2.3:a:realnetworks:realplayer:15.0.1.13
-
cpe:2.3:a:realnetworks:realplayer_sp:1.0.0
-
cpe:2.3:a:realnetworks:realplayer_sp:1.0.1
-
cpe:2.3:a:realnetworks:realplayer_sp:1.0.2
-
cpe:2.3:a:realnetworks:realplayer_sp:1.0.5
-
cpe:2.3:a:realnetworks:realplayer_sp:1.1
-
cpe:2.3:a:realnetworks:realplayer_sp:1.1.1
-
cpe:2.3:a:realnetworks:realplayer_sp:1.1.2
-
cpe:2.3:a:realnetworks:realplayer_sp:1.1.3
-
cpe:2.3:a:realnetworks:realplayer_sp:1.1.4
-
cpe:2.3:a:realnetworks:realplayer_sp:1.1.5