← Back

CVE-2005-2922

nvd nist
Published: Dec 31, 2005Modified: Apr 16, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which either (1) the chunk header length is specified as -1, (2) the chunk header with a length that is less than the actual amount of sent data, or (3) a missing chunk header.

Affected (32)

4 products
Helix Player
Realone Player
Realplayer
Rhapsody
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Realnetworks
Version 10.0.1
Version 10.0.2
Version 10.0.3
Version 10.0.4
Version 10.0.5
Version 10.0.6
Version 10.0
Realnetworks
All versions
Version 0.288
Version 0.297
Version 1.0
Version 2.0
Realnetworks
All versions
Version 10.0.0.305
Version 10.0.0.331
Version 10.0.1
Version 10.0.2
Version 10.0.3
Version 10.0.4
Version 10.0.5
Version 10.0.6
Version 10.0
Version 10.5
Version 10.5_6.0.12.1040
Version 10.5_6.0.12.1053
Version 10.5_6.0.12.1056
Version 10.5_6.0.12.1059
Version 10.5_6.0.12.1069
Version 10.5_6.0.12.1235
Version 8.0
Realnetworks
Version 3.0
Version 3.0_build_0.815

References (24)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.