Unrated severityNVD Advisory· Published Apr 18, 2011· Updated Jun 16, 2026
CVE-2011-1426
CVE-2011-1426
Description
The OpenURLInDefaultBrowser method in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and RealPlayer SP 1.0 through 1.1.5, launches a default handler for the filename specified in the first argument, which allows remote attackers to execute arbitrary code via a .rnx filename corresponding to a crafted RNX file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:realnetworks:realplayer:11.0:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer:11.1:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:realnetworks:realplayer_sp:1.1.5:*:*:*:*:*:*:*
- (no CPE)range: 11.0-11.1, 14.0.0-14.0.2, SP 1.0-1.1.5
Patches
Vulnerability mechanics
References
7- service.real.com/realplayer/security/04122011_player/en/nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0979nvdVendor Advisory
- securitytracker.com/idnvd
- www.securityfocus.com/archive/1/517470/100/0/threadednvd
- www.securityfocus.com/bid/47335nvd
- zerodayinitiative.com/advisories/ZDI-11-122/nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/66728nvd
News mentions
0No linked articles in our index yet.