{"api_version":"1","generated_at":"2026-07-23T15:20:27+00:00","cve":"CVE-2003-1509","urls":{"html":"https://cve.report/CVE-2003-1509","api":"https://cve.report/api/cve/CVE-2003-1509.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1509","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1509"},"summary":{"title":"CVE-2003-1509","description":"Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/8839","name":"http://www.securityfocus.com/bid/8839","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"RealOne Player Temporary File Default Browser Script Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13445","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13445","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://service.real.com/help/faq/security/securityupdate_october2003.html","name":"http://service.real.com/help/faq/security/securityupdate_october2003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Customer Support - RealOne Security Updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1509","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1509","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1509","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realone_enterprise_desktop","cpe6":"6.0.11.774","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1509","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realone_player","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1509","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realone_player","cpe6":"6.0.11.818","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1509","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realone_player","cpe6":"6.0.11.830","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1509","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realone_player","cpe6":"6.0.11.841","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1509","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realone_player","cpe6":"6.0.11.853","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:28:03.721Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://service.real.com/help/faq/security/securityupdate_october2003.html"},{"name":"8839","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8839"},{"name":"realoneplayer-temporary-script-execution(13445)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13445"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-10-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://service.real.com/help/faq/security/securityupdate_october2003.html"},{"name":"8839","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8839"},{"name":"realoneplayer-temporary-script-execution(13445)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13445"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1509","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://service.real.com/help/faq/security/securityupdate_october2003.html","refsource":"CONFIRM","url":"http://service.real.com/help/faq/security/securityupdate_october2003.html"},{"name":"8839","refsource":"BID","url":"http://www.securityfocus.com/bid/8839"},{"name":"realoneplayer-temporary-script-execution(13445)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13445"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1509","datePublished":"2007-10-25T19:00:00.000Z","dateReserved":"2007-10-25T00:00:00.000Z","dateUpdated":"2024-08-08T02:28:03.721Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_enterprise_desktop:6.0.11.774:*:*:*:*:*:*:*","matchCriteriaId":"27DDB6F2-9EAF-4A77-BB3B-D3989E1D9458"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:2.0:*:*:*:*:*:*:*","matchCriteriaId":"CF6535A6-6647-4E60-B5AA-24DFC06360AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.818:*:*:*:*:*:*:*","matchCriteriaId":"0C6BB6A9-B0CE-4C04-8481-53B7CB195264"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.830:*:*:*:*:*:*:*","matchCriteriaId":"41688192-70B7-4C35-AE4F-FE116104137A"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.841:*:*:*:*:*:*:*","matchCriteriaId":"FA11D9CD-113B-4977-B150-D6500552222A"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realone_player:6.0.11.853:*:*:*:*:*:*:*","matchCriteriaId":"BF391DD1-2912-49BF-BC9F-B9FA3771737F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1509","Ordinal":"1","Title":"CVE-2003-1509","CVE":"CVE-2003-1509","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1509","Ordinal":"1","NoteData":"Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser.","Type":"Description","Title":"CVE-2003-1509"},{"CveYear":"2003","CveId":"1509","Ordinal":"2","NoteData":"2007-10-25","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1509","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}