← Back

CVE-2009-4241

nvd nist
Published: Jan 25, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger heap memory corruption.

Affected (18)

4 products
Realplayer
Realplayer Enterprise
Realplayer Sp
Helix Player
Configuration A
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Realnetworks
Version 10.5
Version 11.0.2
Version 11.0.3
Version 11.0.4
Version 11.0.5
All versions
Realnetworks
Version 1.0.0
Version 1.0.1
Running on/withPlatform Versions
Microsoft
Windows
All versions
Configuration B
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Realnetworks
Version 10.0
Version 10.1
Version 11.0.1
Version 11.0
Running on/withPlatform Versions
Apple
Mac Os X
All versions
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Realnetworks
Version 10.0
Version 11.0.0
Version 11.0.1
Realnetworks
Version 10.0
Version 11.0.0
Version 11.0.1

References (16)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.