Realplayer

Vendor:

First CVE: Apr 3, 2000 · Active for 26 years

170
Total CVEs
More Total CVEs than 99% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Realplayer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2000
26 years ago
Most Recent CVE
Jun 5, 2022
1,513 days ago

CVE Severity & Scoring

Realplayer170 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local2 (1.2%)
Network4 (2.4%)
Unknown164 (96.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (3.5%)
High0 (0.0%)
Unknown164 (96.5%)
User Interaction
None2 (1.2%)
Unknown164 (96.5%)
Required4 (2.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (3.5%)
Unknown164 (96.5%)

Top CVEs

Signals from CVEs in this product scope (170 CVEs).

170 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary cod
Jan 3, 20147.577NOYES
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file.
Dec 19, 20129.376NOYES
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 bef
Mar 12, 20089.373NOYES
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object
Oct 19, 20109.369NOYES
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to e
Aug 18, 20119.366NOYES
Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Pl
Oct 20, 20079.365NOYES
Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer
Jun 26, 20079.356NOYES
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, whic
Oct 19, 20109.355NOYES
Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to e
Apr 6, 20119.343NOYES
Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to exec
Aug 30, 20109.342NOYES

Exploit Exposure

Signals from CVEs in this product scope (170 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
3.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
25 CVEs
14.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (170 CVEs).

Media Mentions

Signals from CVEs in this product scope (170 CVEs).

Top CNAs Publishing CVEs For Realplayer

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0267.14.3%01
8338.87.0%05
7.0108.73.8%01
7338.87.0%05
6.044.82.7%01
6338.87.0%05
5338.87.0%05
4338.87.0%05
2.1.578.83.6%00
2.1.4148.27.7%01
2.1.3188.17.1%01
2.1.2318.56.5%02
2.158.43.6%00
20.0.8.31039.73.4%00
20.0.7.30919.84.3%00
2.088.84.0%00
18.1.5.70515.58.1%01
17.0.4.6019.35.2%00
16.0.3.5128.439.1%02
16.0.2.3247.921.4%03