CVE-2011-0694
RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute arbitrary code via the OpenURLinPlayerBrowser function.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 6.58% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- realnetworks/realplayer · realnetworks/realplayer sp
- Source
- cve@mitre.org
References
- http://docs.real.com/docs/security/SecurityUpdate020811RPE.pdfVendor Advisory
- http://osvdb.org/70849
- http://secunia.com/advisories/43268Vendor Advisory
- http://securityreason.com/securityalert/8098
- http://service.real.com/realplayer/security/02082011_player/en/Vendor Advisory
- http://www.securityfocus.com/archive/1/516318/100/0/threaded
- http://www.securitytracker.com/id?1025058
- http://www.zerodayinitiative.com/advisories/ZDI-11-076
- http://docs.real.com/docs/security/SecurityUpdate020811RPE.pdfVendor Advisory
- http://osvdb.org/70849
- http://secunia.com/advisories/43268Vendor Advisory
- http://securityreason.com/securityalert/8098
- http://service.real.com/realplayer/security/02082011_player/en/Vendor Advisory
- http://www.securityfocus.com/archive/1/516318/100/0/threaded
- http://www.securitytracker.com/id?1025058
- http://www.zerodayinitiative.com/advisories/ZDI-11-076
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.