CVE-2006-6847
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument.
- Affected products
- Internet Explorer, Realplayer
- Realnetworks Realplayer
- = 10.5, 10.5_6.0.12.1016_beta, 10.5_6.0.12.1040, 10.5_6.0.12.1053, 10.5_6.0.12.1056, 10.5_6.0.12.1059, 10.5_6.0.12.1069, 10.5_6.0.12.1235
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 6.3% (93th percentile)
- NVD status
- Modified
- Published
- 2007-01-03
CVE-2006-6847 at NVD
1 known exploit for CVE-2006-6847
Proof-of-concept code and exploit modules indexed by Sploitus