CVE-2013-3299
RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string.
- Affected products
- Realplayer
- Realnetworks Realplayer
- ≤ 16.0.2.32, 4, 5, 6, 7, 8, 10.0, 10.5, 11.0, 11.0.1, 11.0.2, 11.0.2.1744, 11.0.2.2315, 11.0.3, 11.0.4, 11.0.5, 11.1, 11.1.3, 11_build_6.0.14.748, 12.0.0.1444, 12.0.0.1548, 14.0.0, 14.0.1, 14.0.1.609, 14.0.2, 14.0.3, 14.0.4, 14.0.5, 15.0.0, 15.0.1.13, 15.0.2.72, 15.0.3.37, 15.0.4, 15.0.4.43, 15.0.5.109, 15.0.6.14, 15.02.71, 16.0.0, 16.0.0.282
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2013-07-06
CVE-2013-3299 at NVD
3 known exploits for CVE-2013-3299
Proof-of-concept code and exploit modules indexed by Sploitus