VYPR
Unrated severityNVD Advisory· Published Oct 31, 2007· Updated Apr 23, 2026

CVE-2007-2263

CVE-2007-2263

Description

Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers.

Affected products

18
  • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1578:windows:*:*:*:*:*+ 14 more
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1578:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1698:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1741:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:*:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.0.305:mac:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.0.331:mac:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.0.352:mac:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.5:linux:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.6:linux:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.7:linux:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.8:linux:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.0:10.0.9:linux:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.1:10.0.0.396:mac:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.1:10.0.0.412:mac:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1040:windows:*:*:*:*:*
  • cpe:2.3:a:realnetworks:realplayer_enterprise:*:*:windows:en:*:*:*:*
  • cpe:2.3:a:realnetworks:realone_player:*:*:mac:en:*:*:*:*+ 1 more
    • cpe:2.3:a:realnetworks:realone_player:*:*:mac:en:*:*:*:*
    • cpe:2.3:a:realnetworks:realone_player:2.0:*:windows:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.