Realplayer
Vendor:
First CVE: Apr 3, 2000 · Active for 26 years
170
Total CVEs
More Total CVEs than 99% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Realplayer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2000
26 years ago
Most Recent CVE
Jun 5, 2022
1,513 days ago
CVE Severity & Scoring
Realplayer170 CVEs
19%
76%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (1.2%)
Network4 (2.4%)
Unknown164 (96.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (3.5%)
High0 (0.0%)
Unknown164 (96.5%)
User Interaction
None2 (1.2%)
Unknown164 (96.5%)
Required4 (2.4%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (3.5%)
Unknown164 (96.5%)
Top CVEs
Signals from CVEs in this product scope (170 CVEs).
170 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7260HIGH Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary cod | Jan 3, 2014 | 7.5 | 77 | NO | YES |
CVE-2012-5691HIGH Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file. | Dec 19, 2012 | 9.3 | 76 | NO | YES |
CVE-2008-1309HIGH The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 bef | Mar 12, 2008 | 9.3 | 73 | NO | YES |
CVE-2010-3747HIGH An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object | Oct 19, 2010 | 9.3 | 69 | NO | YES |
CVE-2011-2950HIGH Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to e | Aug 18, 2011 | 9.3 | 66 | NO | YES |
CVE-2007-5601HIGH Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Pl | Oct 20, 2007 | 9.3 | 65 | NO | YES |
CVE-2007-3410HIGH Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer | Jun 26, 2007 | 9.3 | 56 | NO | YES |
CVE-2010-3749HIGH The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, whic | Oct 19, 2010 | 9.3 | 55 | NO | YES |
CVE-2011-1525HIGH Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to e | Apr 6, 2011 | 9.3 | 43 | NO | YES |
CVE-2010-3000HIGH Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to exec | Aug 30, 2010 | 9.3 | 42 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (170 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
3.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
25 CVEs
14.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (170 CVEs).
Media Mentions
Signals from CVEs in this product scope (170 CVEs).
Top CNAs Publishing CVEs For Realplayer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 26 | 7.1 | 4.3% | 0 | 1 |
| 8 | 33 | 8.8 | 7.0% | 0 | 5 |
| 7.0 | 10 | 8.7 | 3.8% | 0 | 1 |
| 7 | 33 | 8.8 | 7.0% | 0 | 5 |
| 6.0 | 4 | 4.8 | 2.7% | 0 | 1 |
| 6 | 33 | 8.8 | 7.0% | 0 | 5 |
| 5 | 33 | 8.8 | 7.0% | 0 | 5 |
| 4 | 33 | 8.8 | 7.0% | 0 | 5 |
| 2.1.5 | 7 | 8.8 | 3.6% | 0 | 0 |
| 2.1.4 | 14 | 8.2 | 7.7% | 0 | 1 |
| 2.1.3 | 18 | 8.1 | 7.1% | 0 | 1 |
| 2.1.2 | 31 | 8.5 | 6.5% | 0 | 2 |
| 2.1 | 5 | 8.4 | 3.6% | 0 | 0 |
| 20.0.8.310 | 3 | 9.7 | 3.4% | 0 | 0 |
| 20.0.7.309 | 1 | 9.8 | 4.3% | 0 | 0 |
| 2.0 | 8 | 8.8 | 4.0% | 0 | 0 |
| 18.1.5.705 | 1 | 5.5 | 8.1% | 0 | 1 |
| 17.0.4.60 | 1 | 9.3 | 5.2% | 0 | 0 |
| 16.0.3.51 | 2 | 8.4 | 39.1% | 0 | 2 |
| 16.0.2.32 | 4 | 7.9 | 21.4% | 0 | 3 |