{"api_version":"1","generated_at":"2026-07-23T09:52:20+00:00","cve":"CVE-2007-5601","urls":{"html":"https://cve.report/CVE-2007-5601","api":"https://cve.report/api/cve/CVE-2007-5601.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-5601","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-5601"},"summary":{"title":"CVE-2007-5601","description":"Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.","state":"PUBLISHED","assigner":"certcc","published_at":"2007-10-20 20:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/27248","name":"http://secunia.com/advisories/27248","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"RealPlayer Playlist Handling Buffer Overflow Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37280","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37280","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html","name":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Security Response Weblog: RealPlayer Exploit On The Loose","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-297A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-297A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-297A -- RealNetworks RealPlayer ActiveX Playlist Buffer Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/26130","name":"http://www.securityfocus.com/bid/26130","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RealPlayer ierpplug.dll ActiveX Control Import Playlist Name Stack Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1018843","name":"http://www.securitytracker.com/id?1018843","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RealPlayer Input Validation Flaw in 'ierpplug.dll' Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/871673","name":"http://www.kb.cert.org/vuls/id/871673","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#871673 - RealPlayer playlist name stack buffer overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3548","name":"http://www.vupen.com/english/advisories/2007/3548","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.infosecblog.org/2007/10/nasa-bans-ie.html","name":"http://www.infosecblog.org/2007/10/nasa-bans-ie.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NASA Bans IE? - Roger's Information Security Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://service.real.com/realplayer/security/191007_player/en/","name":"http://service.real.com/realplayer/security/191007_player/en/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RealPlayer and StarSearch by Real Official Homepage — Real.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-5601","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-5601","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"5601","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realplayer","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5601","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realplayer","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"5601","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"realnetworks","cpe5":"realplayer","cpe6":"11_beta","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-5601","organization":"Red Hat","lastmodified":"2007-10-23","contributor":"Mark J Cox","statementText":"Not vulnerable. This issue did not affect versions of RealPlayer as shipped with Red Hat Enterprise Linux 3 and 4 Extras or with Red Hat Enterprise Linux 5 Supplementary.","cve_year":"2007","cve_id":"5601","crc32":"271d26c8"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:39:13.073Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27248","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27248"},{"name":"VU#871673","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/871673"},{"name":"1018843","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018843"},{"name":"ADV-2007-3548","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3548"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.infosecblog.org/2007/10/nasa-bans-ie.html"},{"name":"26130","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/26130"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html"},{"name":"TA07-297A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-297A.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://service.real.com/realplayer/security/191007_player/en/"},{"name":"realplayer-activex-bo(37280)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37280"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"27248","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27248"},{"name":"VU#871673","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/871673"},{"name":"1018843","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018843"},{"name":"ADV-2007-3548","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3548"},{"tags":["x_refsource_MISC"],"url":"http://www.infosecblog.org/2007/10/nasa-bans-ie.html"},{"name":"26130","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/26130"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html"},{"name":"TA07-297A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-297A.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://service.real.com/realplayer/security/191007_player/en/"},{"name":"realplayer-activex-bo(37280)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37280"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-5601","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27248","refsource":"SECUNIA","url":"http://secunia.com/advisories/27248"},{"name":"VU#871673","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/871673"},{"name":"1018843","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018843"},{"name":"ADV-2007-3548","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3548"},{"name":"http://www.infosecblog.org/2007/10/nasa-bans-ie.html","refsource":"MISC","url":"http://www.infosecblog.org/2007/10/nasa-bans-ie.html"},{"name":"26130","refsource":"BID","url":"http://www.securityfocus.com/bid/26130"},{"name":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html","refsource":"MISC","url":"http://www.symantec.com/enterprise/security_response/weblog/2007/10/realplayer_exploit_on_the_loos.html"},{"name":"TA07-297A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-297A.html"},{"name":"http://service.real.com/realplayer/security/191007_player/en/","refsource":"CONFIRM","url":"http://service.real.com/realplayer/security/191007_player/en/"},{"name":"realplayer-activex-bo(37280)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/37280"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-5601","datePublished":"2007-10-20T20:00:00.000Z","dateReserved":"2007-10-20T00:00:00.000Z","dateUpdated":"2024-08-07T15:39:13.073Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-10-20 20:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*","matchCriteriaId":"CD49D16C-B0AC-4228-9984-010661596232"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*","matchCriteriaId":"348F3214-E5C2-4D39-916F-1B0263D13F40"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:realplayer:11_beta:*:*:*:*:*:*:*","matchCriteriaId":"64C3CD7C-9CD8-4BC3-9ECE-CE39FB02E602"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"5601","Ordinal":"1","Title":"CVE-2007-5601","CVE":"CVE-2007-5601","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"5601","Ordinal":"1","NoteData":"Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl ActiveX control in ierpplug.dll.","Type":"Description","Title":"CVE-2007-5601"},{"CveYear":"2007","CveId":"5601","Ordinal":"2","NoteData":"2007-10-20","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"5601","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}