VYPR
Unrated severityNVD Advisory· Published Oct 31, 2007· Updated Apr 23, 2026

CVE-2007-5080

CVE-2007-5080

Description

Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.

Affected products

8
  • cpe:2.3:a:realnetworks:realone_player:1.0:*:windows:en:*:*:*:*+ 1 more
    • cpe:2.3:a:realnetworks:realone_player:1.0:*:windows:en:*:*:*:*
    • cpe:2.3:a:realnetworks:realone_player:2.0:*:windows:*:*:*:*:*
  • cpe:2.3:a:realnetworks:realplayer:10.0:*:windows:*:*:*:*:*+ 4 more
    • cpe:2.3:a:realnetworks:realplayer:10.0:*:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1040:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1578:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1698:windows:*:*:*:*:*
    • cpe:2.3:a:realnetworks:realplayer:10.5:6.0.12.1741:windows:*:*:*:*:*
  • cpe:2.3:a:realnetworks:realplayer_enterprise:*:*:windows:en:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.