SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-0694

RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute…

HIGH 9.3EPSS 6.58%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute arbitrary code via the OpenURLinPlayerBrowser function.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
6.58% probability · 93th percentile
CISA KEV
Not listed
Affected
realnetworks/realplayer · realnetworks/realplayer sp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.