CVE-2008-1309 describes a critical heap corruption vulnerability in the RealAudioObjects.RealAudio ActiveX control (rmoc3260.dll) affecting RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5, and RealPlayer 11. This flaw allows remote attackers to execute arbitrary code or cause a denial of service by sending specially crafted long string values to the Console or Controls property, leading to an overwrite of freed heap memory. With a CVSS score of 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C) and a FAUCET Risk Score of 100/100, this vulnerability is highly severe, requiring no authentication and moderate attack complexity, with complete confidentiality, integrity, and availability impacts. While not on the KEV catalog, exploit code is publicly available, including a Metasploit module and ExploitDB entries, and it has garnered significant community discussion with 10 mentions, indicating active interest and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:*:*:enterprise:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:10.0:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:10.5:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.