CVE-2006-0323
Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations.
- Affected products
- Helix Player, Realone Player, Realplayer, Rhapsody
- Realnetworks Helix Player
- All versions
- Realnetworks Realone Player
- All versions
- Realnetworks Realplayer
- = 10.0, 10.0.6, 10.5
- Realnetworks Rhapsody
- = 3
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 16.7% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2006-03-23
CVE-2006-0323 at NVD
10 known exploits for CVE-2006-0323
Proof-of-concept code and exploit modules indexed by Sploitus
RealNetworks Multiple Products Multiple Buffer Overflow Vulnerabilities
RealPlayer <= 10.5 (6.0.12.1040-1348) - SWF Buffer Overflow PoC
RealPlayer 10.5 (6.0.12.1040-1348) SWF Buffer Overflow PoC
realplayer-swf-PoC.pl.txt
RealPlayer 10.5 (6.0.12.1040-1348) - SWF Buffer Overflow (PoC)
RealPlayer <= 10.5 (6.0.12.1040-1348) SWF Buffer Overflow PoC
RealPlayer 10.5 (6.0.12.1040-1348) - SWF Buffer Overflow (PoC)
RealPlayer <= 10.5 (6.0.12.1040-1348) SWF Buffer Overflow PoC
RealNetworks (Multiple Products) - Multiple Buffer Overflow Vulnerabilities
RealNetworks (Multiple Products) - Multiple Buffer Overflow Vulnerabilities