Multiple RealNetworks Products Multiple Remote Vulnerabilities

BID:37880

Info

Multiple RealNetworks Products Multiple Remote Vulnerabilities

Bugtraq ID: 37880
Class: Boundary Condition Error
CVE: CVE-2009-4241
CVE-2009-4242
CVE-2009-4243
CVE-2009-4244
CVE-2009-4245
CVE-2009-4257
CVE-2009-4248
CVE-2009-4247
CVE-2009-4246
Remote: Yes
Local: No
Published: Jan 20 2010 12:00AM
Updated: Jul 13 2010 08:27PM
Credit: Evgeny Legerov, anonymous researchers working with iDEFENSE Labs, John Rambo, Peter Vreugdenhil working with TippingPoint's Zero Day Initiative, and anonymous researchers working with TippingPoint's Zero Day Initiative
Vulnerable: Sun Solaris 10_x86
Sun Solaris 10_sparc
Redhat Enterprise Linux WS 4
Redhat Enterprise Linux ES 4
Redhat Enterprise Linux AS 4
Redhat Enterprise Linux Desktop version 4
RealNetworks RealPlayer SP 1.0.1
RealNetworks RealPlayer SP 1.0
RealNetworks RealPlayer Enterprise 1.7
RealNetworks RealPlayer Enterprise 1.6
RealNetworks RealPlayer Enterprise 1.5
RealNetworks RealPlayer Enterprise 1.2
RealNetworks RealPlayer Enterprise 1.1
RealNetworks RealPlayer Enterprise
RealNetworks RealPlayer 10 for Mac OS 10.0 .0.331
RealNetworks RealPlayer 10 for Mac OS 10.0.0.503
RealNetworks RealPlayer 10 for Mac OS 10.0.0.481
RealNetworks RealPlayer 10 for Mac OS 10.0.0.412
RealNetworks RealPlayer 10 for Mac OS 10.0.0.396
RealNetworks RealPlayer 10 for Mac OS 10.0.0.352
RealNetworks RealPlayer 10 for Mac OS 10.0.0.325
RealNetworks RealPlayer 10 for Mac OS 10.0.0.305
RealNetworks RealPlayer 10 for Mac OS
RealNetworks RealPlayer 10 for Linux 10.1 .3114
RealNetworks RealPlayer 10 for Linux 10.0.9
RealNetworks RealPlayer 10 for Linux 10.0.8
RealNetworks RealPlayer 10 for Linux 10.0.7
RealNetworks RealPlayer 10 for Linux 10.0.6
RealNetworks RealPlayer 10 for Linux 10.0.5
RealNetworks RealPlayer 10 for Linux 10.0.4
RealNetworks RealPlayer 10 for Linux 10.0.3
RealNetworks RealPlayer 10 for Linux 10.0.2
RealNetworks RealPlayer 10 for Linux 10.0.1
RealNetworks RealPlayer 10 for Linux
RealNetworks RealPlayer 11.0.5
RealNetworks RealPlayer 11.0.4
RealNetworks RealPlayer 11.0.3
RealNetworks RealPlayer 11.0.2
RealNetworks RealPlayer 11.0.1
RealNetworks RealPlayer 10.5 v6.0.12.1741
RealNetworks RealPlayer 10.5 v6.0.12.1698
RealNetworks RealPlayer 10.5 v6.0.12.1675
RealNetworks RealPlayer 10.5 v6.0.12.1663
RealNetworks RealPlayer 10.5 v6.0.12.1483
RealNetworks RealPlayer 10.5 v6.0.12.1348
RealNetworks RealPlayer 10.5 v6.0.12.1235
RealNetworks RealPlayer 10.5 v6.0.12.1069
RealNetworks RealPlayer 10.5 v6.0.12.1059
RealNetworks RealPlayer 10.5 v6.0.12.1056
RealNetworks RealPlayer 10.5 v6.0.12.1053
RealNetworks RealPlayer 10.5 v6.0.12.1040
RealNetworks RealPlayer 10.5
RealNetworks RealPlayer 11
Not Vulnerable:

Exploit / POC

Multiple RealNetworks Products Multiple Remote Vulnerabilities

Currently we are not aware of any working exploits for some of these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Working commercial exploits are available through VUPEN Security - Exploit and PoCs Service for CVE-2009-4248 and CVE-2009-4244. These exploits are not otherwise publicly available or known to be circulating in the wild.

A commercial exploit is available through the VulnDisco pack for CVE-2009-4247. This exploit is not otherwise publicly available or known to be circulating in the wild.

References

Multiple RealNetworks Products Multiple Remote Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report