Realplayer Sp

Vendor:

First CVE: Jan 25, 2010 · Active for 16 years

82
Total CVEs
More Total CVEs than 99% of tracked products
20.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.8
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Realplayer Sp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2010
16 years ago
Most Recent CVE
Aug 27, 2013
4,718 days ago

CVE Severity & Scoring

Realplayer Sp82 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown82 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown82 (100.0%)
User Interaction
None0 (0.0%)
Unknown82 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown82 (100.0%)

Top CVEs

Signals from CVEs in this product scope (82 CVEs).

82 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a crafted RealMedia file.
Dec 19, 20129.376NOYES
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object
Oct 19, 20109.369NOYES
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to e
Aug 18, 20119.366NOYES
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, whic
Oct 19, 20109.355NOYES
Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to exec
Aug 30, 20109.342NOYES
Unspecified vulnerability in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code vi
Feb 8, 20129.331NONO
Unspecified vulnerability in an ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2
Aug 18, 201110.031NONO
The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows
Feb 8, 20129.330NONO
Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute
Feb 8, 20129.330NONO
Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allows remote attackers to execu
Dec 14, 20109.330NONO

Exploit Exposure

Signals from CVEs in this product scope (82 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
7.3% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (82 CVEs).

Media Mentions

Signals from CVEs in this product scope (82 CVEs).

Top CNAs Publishing CVEs For Realplayer Sp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1.5468.65.6%02
1.1.4668.85.8%05
1.1.3678.85.8%06
1.1.2678.85.8%06
1.1.1698.85.8%06
1.1698.85.8%06
1.0.5698.85.8%06
1.0.2698.85.8%06
1.0.1818.95.9%06
1.0.0818.95.9%06