CVE-2011-2954
Summary
| CVE | CVE-2011-2954 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-08-18 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Use-after-free vulnerability in the AutoUpdate feature in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5, when an Embedded RealPlayer is used, allows remote attackers to execute arbitrary code via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realnetworks | Realplayer | 11.0 | All | All | All |
| Application | Realnetworks | Realplayer | 11.1 | All | All | All |
| Application | Realnetworks | Realplayer | 14.0.0 | All | All | All |
| Application | Realnetworks | Realplayer | 14.0.1 | All | All | All |
| Application | Realnetworks | Realplayer | 14.0.2 | All | All | All |
| Application | Realnetworks | Realplayer | 14.0.3 | All | All | All |
| Application | Realnetworks | Realplayer | 14.0.4 | All | All | All |
| Application | Realnetworks | Realplayer | 14.0.5 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.0.0 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.0.1 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.0.2 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.0.5 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.1 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.1.1 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.1.2 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.1.3 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.1.4 | All | All | All |
| Application | Realnetworks | Realplayer Sp | 1.1.5 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| August 2011 Update | af854a3a-2127-422b-91ae-364da2661108 | service.real.com | Vendor Advisory |
| RealPlayer Flaws Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.