VulnerabilityModified
CVE-2010-1317
Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.
HIGH 7.5EPSS 1.62%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- realnetworks/helix dna server · realnetworks/helix server · realnetworks/helix server mobile
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/39279Vendor Advisory
- http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdfVendor Advisory
- http://www.securityfocus.com/bid/39490
- http://www.vupen.com/english/advisories/2010/0889Vendor Advisory
- http://secunia.com/advisories/39279Vendor Advisory
- http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdfVendor Advisory
- http://www.securityfocus.com/bid/39490
- http://www.vupen.com/english/advisories/2010/0889Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.