Realserver

Vendor:

First CVE: Jan 15, 1998 · Active for 28 years

8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Realserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 15, 1998
28 years ago
Most Recent CVE
Oct 20, 2003
8,316 days ago

CVE Severity & Scoring

Realserver8 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and R
Oct 20, 20037.558NOYES
Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.
Jun 1, 20007.833NOYES
RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.
Apr 20, 20007.833NOYES
RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.
Dec 23, 19995.026NOYES
Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin
Jan 9, 20015.025NOYES
RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.
Mar 8, 20005.024NOYES
pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
Jan 15, 19987.820NONO
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.
Apr 14, 19994.614NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
75.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Realserver

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
pro17.89.4%01
plus17.89.4%01
intranet17.89.4%01
g2_1.027.731.4%02
basic17.89.4%01
8.0_beta27.731.5%02
8.0.217.553.5%01
8.0.117.553.5%01
8.017.553.5%01
7.0.217.553.5%01
7.0.127.731.5%02
7.056.617.1%05
6.0.3.35314.60.9%00
6.015.07.8%01
5.045.75.3%03