Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-1309

73
FAUCET Score

CVE-2008-1309 describes a critical heap corruption vulnerability in the RealAudioObjects.RealAudio ActiveX control (rmoc3260.dll) affecting RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5, and RealPlayer 11. This flaw allows remote attackers to execute arbitrary code or cause a denial of service by sending specially crafted long string values to the Console or Controls property, leading to an overwrite of freed heap memory. With a CVSS score of 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C) and a FAUCET Risk Score of 100/100, this vulnerability is highly severe, requiring no authentication and moderate attack complexity, with complete confidentiality, integrity, and availability impacts. While not on the KEV catalog, exploit code is publicly available, including a Metasploit module and ExploitDB entries, and it has garnered significant community discussion with 10 mentions, indicating active interest and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:realnetworks:realplayer:*:*:enterprise:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:*
10.5CPE matchmatch criteria
cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:a:realnetworks:realplayer:11:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
45.95%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: RealPlayer rmoc3260.dll ActiveX Control Heap Corruption · Mar 8, 2008
ExploitDB: EDB-16584 · Jun 15, 2010
This CVE's current EPSS score of 0.4595 is in the 98th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2008-1309

CVE-2008-1309

References

lists.grok.org.uk / pipermail/full-disclosure/2008-March/060659.html
secunia.com / advisories/29315
Vendor Advisory
service.real.com / realplayer/security/07252008_player/en
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/41087
exploit-db.com / exploits/5332
kb.cert.org / vuls/id/831457
US Government Resource
securityfocus.com / archive/1/494779/100/0/threaded
securityfocus.com / bid/28157
Exploit
securitytracker.com / id
securitytracker.com / id
vupen.com / english/advisories/2008/0842
Vendor Advisory
vupen.com / english/advisories/2008/2194/references
Vendor Advisory
zerodayinitiative.com / advisories/ZDI-08-047