CVE-2010-1317
Summary
| CVE | CVE-2010-1317 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-20 15:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realnetworks | Helix Dna Server | 11.0 | All | All | All |
| Application | Realnetworks | Helix Dna Server | 11.1 | All | All | All |
| Application | Realnetworks | Helix Dna Server | 11.1.2 | All | All | All |
| Application | Realnetworks | Helix Dna Server | 11.1.3 | All | All | All |
| Application | Realnetworks | Helix Dna Server | 12.0 | All | All | All |
| Application | Realnetworks | Helix Dna Server | 13.0 | All | All | All |
| Application | Realnetworks | Helix Server | 11.0 | All | All | All |
| Application | Realnetworks | Helix Server | 11.1 | All | All | All |
| Application | Realnetworks | Helix Server | 12.0.0 | All | All | All |
| Application | Realnetworks | Helix Server | 13.0.0 | All | All | All |
| Application | Realnetworks | Helix Server Mobile | 11.0 | All | All | All |
| Application | Realnetworks | Helix Server Mobile | 12.0.0 | All | All | All |
| Application | Realnetworks | Helix Server Mobile | 13.0.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RealNetworks Helix and Helix Mobile Server NTLM Authentication Heap Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Helix Server and Helix Mobile Server Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| 404 | Realnetworks | af854a3a-2127-422b-91ae-364da2661108 | www.realnetworks.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.